Vague Triggers
Medium
- Confidence
- 94% confidence
- Finding
- The routing table sends 'Everything else' to the SSE action, which effectively captures nearly any unmatched user prompt and forwards it to the third-party backend. That broad fallback increases the chance of unintended invocation, accidental data disclosure, and user requests being processed by a remote service without sufficiently explicit scoping or confirmation.
