Vague Triggers
Medium
- Confidence
- 83% confidence
- Finding
- The invocation guidance is very broad: 'Generate an invoice for:' and 'The agent will use this skill' do not clearly constrain when the skill should trigger. In an agent environment, ambiguous triggers can cause unintended activation on loosely related prompts, increasing the chance of mishandling user data or generating documents from incomplete or attacker-supplied content.
