Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The skill defines a very broad trigger phrase ('secrets-scanner') relative to its security-sensitive functionality, and the description also advertises generic terms like 'security scan' and 'check api key'. Broad or underspecified activation can cause the skill to run in unintended contexts, potentially scanning repositories or exposing sensitive matches when the user did not clearly request that action.
