Vague Triggers
Medium
- Confidence
- 87% confidence
- Finding
- The manifest uses very broad trigger phrases like 'check email', 'send email', and 'manage domain', which can cause the skill to activate for common user requests with significant access to mailbox, alias, and landing-page operations. Over-broad invocation increases the chance of unintended tool use against sensitive email content or account configuration, especially in an agentic environment.
