Vague Triggers
Medium
- Confidence
- 92% confidence
- Finding
- The README explicitly states that after copying a template, the agent 'picks it up automatically,' but it does not define clear guardrails for when the heartbeat runs, what permissions it uses, or how to limit execution scope. For a background task system that may access email, calendars, system health, repos, and social platforms, vague auto-activation language can lead users to enable persistent monitoring without understanding the operational boundaries or data exposure.
