Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The trigger phrases "Research" or "Summarize" are very broad and likely to overlap with many normal user requests, which can cause the skill to activate unexpectedly. Because this skill spawns a worker session and fetches external URLs, unintended invocation can expand the attack surface, create unnecessary external requests, and enable prompt-injection exposure from arbitrary web content.
