Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The trigger language is broad enough that ordinary user phrasing like 'ask quorumai' or 'run a quorumai inquiry' can cause the agent to forward the user's prompt to a third-party service without a clear confirmation step. This increases the risk of unintended data disclosure, especially when users include sensitive or regulated information in what they think is a normal conversation.
