Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The skill description and details describe a broadly-scoped capability that can scan all installed skills and generate a merged requirements file, but they do not define clear invocation boundaries, user confirmation requirements, or exclusions for sensitive directories. In an agent setting, overly broad trigger criteria can cause the skill to run in unintended contexts, exposing dependency metadata across projects or modifying package plans without explicit user intent.
