Vague Triggers
Medium
- Confidence
- 84% confidence
- Finding
- The routing table sends nearly all unmatched user input to the remote SSE action, creating a broad catch-all path that can cause unintended transmission of prompts and file-processing requests to the backend. In a skill that handles user media and free-form instructions, this increases the chance of accidental remote actions, privacy surprises, and misuse of external services without sufficiently explicit user intent.
