Vague Triggers
Medium
- Confidence
- 84% confidence
- Finding
- The trigger guidance is broad enough that the skill may be invoked for generic requests such as 'read a URL' or 'scrape,' which can cause unintended external network access. In an agent system, over-broad routing increases the chance of fetching attacker-controlled URLs or sensitive internal endpoints when a safer or more constrained tool should have been used.
