Vague Triggers
Medium
- Confidence
- 81% confidence
- Finding
- The README tells users to simply invoke the skill and send long company introductions, but it does not define clear activation boundaries, allowed inputs, or output constraints. In agentic environments, vague invocation guidance can cause the skill to be triggered in unintended contexts, increasing the chance of accidental processing of unrelated, sensitive, or attacker-supplied content.
