Vague Triggers
Medium
- Confidence
- 93% confidence
- Finding
- The routing table sends virtually all unmatched prompts to the SSE edit path via an 'Everything else' catch-all. In a chat-based agent, this can cause over-broad invocation and unintended transmission of arbitrary user text, files, or requests to the external Nemo service, increasing the chance of data leakage, confused-deputy behavior, and accidental tool activation outside the user's intended scope.
