Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The AI-trigger guidance is broad enough that an agent may invoke the skill whenever a user mentions parsing a document or supplies a URL, without confirming that the user wants third-party OCR processing. Because the skill sends document URLs and derived content to an external service, ambiguous triggering increases the risk of unintended data disclosure.
