Vague Triggers
Medium
- Confidence
- 93% confidence
- Finding
- The usage section includes broad prompts like 'Is this wallet safe to interact with?' and 'Profile this trader before I copy their trades,' which can cause an agent to invoke the skill opportunistically without strong user confirmation. In this skill's context, that is more dangerous because each invocation can trigger a paid external request, so ambiguous activation can lead to unintended spending and external data disclosure about user-supplied addresses.
