Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The README states the skill can be invoked not only by an explicit command but also when a user 'just paste[s] an agent instruction file in a conversation where the skill is active.' That creates an overly broad activation condition that may cause unintentional processing of pasted content, increasing the chance of surprise execution, data exposure, or prompt-driven behavior on content the user did not mean to submit to this skill.
