Vague Triggers
Medium
- Confidence
- 92% confidence
- Finding
- The instruction to invoke Arsenal for anything 'blockchain-related' is overly broad and can cause the agent to activate this skill for read-only, sensitive, or tangential crypto requests without clear user consent. Because this skill can lead to transaction construction and wallet-oriented workflows, broad triggering increases the chance of unintended high-risk actions or unnecessary data sharing to a third-party API.
