Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The skill’s trigger scope is overly broad, covering many generic intents such as auditing, cloning, markdown export, sitemap generation, stress testing, and CI/CD checks without clear gating or exclusions. This can cause unintended invocation on sensitive or production targets, increasing the chance the agent performs network-heavy, intrusive, or externally visible actions when the user did not explicitly consent to them.
