Vague Triggers
Medium
- Confidence
- 87% confidence
- Finding
- The README advertises very broad trigger phrases such as comparing 'these two Word documents' and says the agent will automatically read SKILL.md, invoke scripts, and return an output file. Without tighter scope constraints and explicit input-validation guidance, this can cause over-activation or activation on untrusted/mis-scoped files, increasing the chance the skill processes sensitive documents unexpectedly or is invoked in workflows where safer review should occur first.
