Vague Triggers
Medium
- Confidence
- 84% confidence
- Finding
- The README shows a natural-language trigger that can cause the skill to fetch and extract content from an arbitrary user-provided URL without documenting scope restrictions, trust boundaries, or approval requirements. In an agent setting with network permission, this broad phrasing can encourage unsafe use such as fetching internal resources, attacker-controlled URLs, or sensitive endpoints, increasing SSRF-like and data-handling risk.
