Vague Triggers
Medium
- Confidence
- 87% confidence
- Finding
- The slash-command description advertises that `/ai-dev-runtime <task>` will run a full development workflow for an arbitrary task, including planning, editing, testing, and fixing. Because the trigger wording is broad and task input is unconstrained, users or upstream agents may invoke powerful file-editing and terminal-capable behavior on vague or unsafe requests, increasing the risk of unintended code changes or command execution.
