Vague Triggers
Medium
- Confidence
- 88% confidence
- Finding
- The README instructs agents to invoke the skill automatically whenever a reply would contain LaTeX, without requiring user intent, cost/benefit checks, or scope limits. This can cause unnecessary tool execution and file generation on ordinary math/science responses, expanding attack surface and enabling prompt-triggered resource consumption or unintended side effects.
