Vague Triggers
Medium
- Confidence
- 84% confidence
- Finding
- The skill includes a broad natural-language invocation to perform a comprehensive code security audit, which in this skill context can trigger large-scale scanning and report generation across the current project. Because the skill has exec capability and examples that write artifacts, an underspecified trigger increases the risk of unintended workspace-wide actions, excessive resource usage, or execution on sensitive repositories without explicit scoping confirmation.
