Vague Triggers
Medium
- Confidence
- 83% confidence
- Finding
- The skill description is broad enough that an agent may invoke it for many generic 'make a video' requests without sufficient user confirmation or routing specificity. This can cause unintended external API use, unexpected costs, and accidental transmission of user prompts to a third-party service, which is a real security and privacy concern in an auto-invocation system.
