Vague Triggers
Medium
- Confidence
- 82% confidence
- Finding
- The routing rule sends 'Everything else' to the SSE action, creating an overly broad catch-all path for arbitrary user input. In a skill that uploads content and interacts with a remote third-party backend, ambiguous activation increases the chance of unintended transmission of user prompts or files to the external service.
