Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- Allowing activation when 'other skills/tools return a message containing instructions to use Alipay payment' creates an instruction-injection path where untrusted tool output can drive a payment workflow. Because this skill is capable of checking wallet state, initiating authorization flow, and submitting payment requests, unclear trust boundaries around tool messages materially increase the chance of unauthorized or manipulated payment actions.
