Vague Triggers
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to 'directly invoke' on broad natural-language search intent, with examples that cover generic phrases like '帮我搜一下美食' and '看看抖音热榜' but no boundary checks, confirmation rules, or disambiguation requirements. This can cause overbroad automatic execution of a networked scraper, leading to unintended external requests, surprise automation, or invocation when the user was only asking informationally rather than authorizing an action. The risk is higher here because the skill performs live scraping/browser automation rather than a harmless local transformation.
