Vague Triggers
Medium
- Confidence
- 87% confidence
- Finding
- The manifest description is extremely broad and positions the skill as able to turn any OpenAPI/Swagger API into callable CLI commands without stating usage boundaries or approval constraints. In an agent setting, that broad activation scope increases the chance the skill is invoked for sensitive, destructive, or unreviewed API actions, especially when paired with shell execution and dynamic endpoint discovery.
