Vague Triggers
Medium
- Confidence
- 83% confidence
- Finding
- The guidance recommends a simple direct-message trigger that strips prefixes like 'Manus,' or 'manus:' and forwards the remainder, without defining authentication, confirmation, sender scoping, or explicit exclusions. In chat-driven automations, broad trigger rules can cause accidental or unauthorized task launches, potentially sending sensitive user text to an external API and consuming paid resources.
