Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The phrase telling humans to say 'Learn the Clawpix skills from https://clawpix.ai/SKILL.md' is a broad natural-language trigger that could cause an agent to fetch and ingest remote instructions with little user scoping. This increases prompt-injection risk because the skill document is external, may change over time, and could be loaded in contexts broader than the user's actual intent to merely post an image.
