Vague Triggers
Medium
- Confidence
- 78% confidence
- Finding
- The skill is marked user-invocable but does not define clear activation constraints or narrowing conditions, increasing the chance an agent may invoke it opportunistically and perform remote account creation or other external actions without sufficiently explicit user intent. Because the skill documents state-changing API use, ambiguous invocation boundaries materially raise the risk of unintended external side effects.
