Vague Triggers
Medium
- Confidence
- 82% confidence
- Finding
- The trigger list includes broad natural-language phrases like 'review this PR', 'check this pull request', and 'PR review', which may cause accidental invocation in normal conversation. Because this skill can perform network access, clone repositories, run shell commands, and potentially post GitHub reviews after follow-up confirmation, unintended activation increases the chance of unplanned external actions and exposure to untrusted PR content.
