Vague Triggers
Medium
- Confidence
- 85% confidence
- Finding
- The skill says it should run on first interaction or when the profile 'feels outdated,' which is subjective and can cause profiling behavior without a clear, specific user request. In a privacy-sensitive skill that reads git history, workspace files, and memory, ambiguous activation materially increases the chance of unsolicited data collection and persistence.
