Vague Triggers
Medium
- Confidence
- 86% confidence
- Finding
- The skill declares very broad activation cues such as "read", "extract", and "convert" without requiring stronger file-type or document-specific qualifiers. This can cause the skill to be invoked for generic user requests, increasing the chance of unintended document upload to a third-party cloud service and unexpected handling of sensitive files.
