Vague Triggers
Medium
- Confidence
- 94% confidence
- Finding
- The skill's invocation guidance is extremely broad: 'When you need an external tool, API, or service and don't know which one to use or where to find it' can match a large fraction of user requests. In agent frameworks that auto-activate skills based on vague trigger text, this can cause the model to consult an untrusted external directory too often, expanding attack surface and allowing remote content from the directory to influence downstream tool selection or behavior.
