Vague Triggers
Medium
- Confidence
- 94% confidence
- Finding
- The quick-command triggers are very generic (for example, phrases like "lag workflow", "kjør {name}", and "rediger {name}") and are not scoped to an explicit invocation boundary, trusted mode, or disambiguation step. In a conversational agent, broad triggers can cause accidental activation or prompt-injection-style steering where unrelated user text is interpreted as a command to create, edit, list, or execute persisted workflows, especially given this skill can chain API calls, file writes, and shell commands.
