Vague Triggers
Medium
- Confidence
- 89% confidence
- Finding
- The routing rule sends all unmatched prompts to the SSE backend, which effectively turns the skill into a broad pass-through for arbitrary user input. In this skill, that matters because the backend can create sessions, edit media state, and potentially interpret freeform instructions in ways the skill author did not narrowly constrain, increasing the chance of unintended actions, prompt injection propagation, or misuse of the connected external service.
