Vague Triggers
Medium
- Confidence
- 93% confidence
- Finding
- This skill grants direct payment capability over Lightning using a secret-bearing NWC connection string, but the invocation scope is described in broad, empowering language rather than with explicit approval gates, permitted use cases, or hard transaction constraints. In a financial skill, unclear scope can lead an agent to autonomously initiate payments in response to ambiguous prompts or social-engineering scenarios, causing unauthorized fund transfers.
