Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The description includes a broad catch-all trigger ('Other actions if you need to use Stata') in addition to many common Stata tasks, which can cause the skill to activate for a wide range of ordinary requests. Over-broad activation increases the chance an agent invokes code-execution or package-installation capabilities unnecessarily, expanding attack surface and creating opportunities for unsafe tool use on untrusted inputs.
