Vague Triggers
Medium
- Confidence
- 90% confidence
- Finding
- The skill advertises trigger phrases such as "manage my goals", "create a task", and especially generic product references like "goal tracking", which are broad enough to match common user requests outside this specific integration. That can cause unintended invocation of a capability that performs real read/write actions against an external SaaS using a privileged API key, increasing the chance of accidental data access or modification.
