Vague Triggers
Medium
- Confidence
- 94% confidence
- Finding
- The manifest description includes unrelated, nonspecific words such as place names and random terms that do not belong to the WordPress/MCP domain. This kind of trigger-like padding is suspicious because it can manipulate routing, discovery, or prompt matching behavior, causing the skill to be invoked in unintended contexts and expanding access to powerful admin capabilities.
