Vague Triggers
Medium
- Confidence
- 92% confidence
- Finding
- The skill description says it should be used for 'any mail-related operation,' which is broad enough to be triggered by ordinary conversation about email rather than an explicit request to access or modify a mailbox. In a skill that can read, send, forward, delete mail, and perform OAuth login, over-broad activation increases the chance of unintended tool use and exposure of sensitive mailbox data.
