Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The skill advertises very broad natural-language triggers such as "读取 C:\path\to\file.docx" and says it will automatically invoke the office-reader script, but it does not define clear trigger boundaries, confirmation requirements, or exclusions. In an agent setting, this can cause unintended local file access when a user message merely mentions a path or when untrusted content includes file paths that the agent interprets as an instruction.
