Vague Triggers
Medium
- Confidence
- 86% confidence
- Finding
- The skill description and capability list are very broad, but the file does not define activation boundaries, allowed tasks, or explicit scope constraints. In an agent setting, this can cause overbroad invocation and unintended assistance in adjacent domains, increasing the chance of unsafe or privacy-impacting behavior even if no direct exploit code is present.
