Vague Triggers
Medium
- Confidence
- 83% confidence
- Finding
- The skill advertises broad, conversational triggers like helping inspect PRs and Issues without clearly defining activation boundaries, authorized repositories, or read-only vs write scopes. In an agent setting, vague invocation patterns can cause overbroad activation and unintended access to GitHub data or operations when the user did not explicitly request this skill.
