Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The skill advertises activation on vague, everyday phrases such as 'view stats' and a broad condition like wanting to see performance data, which can cause the agent to invoke this skill in contexts the user did not specifically intend. Because the skill exposes analytics across multiple connected social accounts and relies on an MCP URL containing embedded auth, accidental invocation can lead to unnecessary access and disclosure of sensitive performance data.
