Vague Triggers
Medium
- Confidence
- 88% confidence
- Finding
- The skill description is broad enough to trigger on many generic requests to 'read' or 'generate audio' without clearly warning that user text will be sent to a third-party API and written to disk. This can cause unintended activation on sensitive content, increasing the chance of exfiltrating private text to an external service.
