Vague Triggers
Medium
- Confidence
- 82% confidence
- Finding
- The manifest description advertises broad Markdown-to-image conversion capabilities but does not constrain when the skill should be invoked or what classes of content are appropriate. In an agent setting, this can cause over-selection of the skill for unrelated user inputs, leading to unnecessary network/file access and unintended exfiltration of user content to external services mentioned in the skill.
