Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The skill's activation guidance is broad enough that an agent may invoke it whenever a user asks to 'read' or 'extract' an image, without clearly surfacing that the image will be uploaded to a third-party cloud service. Because the skill accepts both local files and URLs and advertises 'no API key' convenience, it increases the chance of accidental exfiltration of sensitive screenshots, documents, or photos to an external provider.
