Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The skill description includes broad natural-language trigger phrases such as 'design an image', 'create a poster', and 'make a thumbnail', which can cause the skill to be invoked in situations where the user did not explicitly intend to use this third-party cloud service. Because the skill has write/delete/export capabilities and uses a bearer-style embedded MCP token, unintended invocation could lead to unnecessary data exposure to the external service or accidental modification/export of projects.
