Vague Triggers
Medium
- Confidence
- 95% confidence
- Finding
- The trigger phrase “帮我接收支付宝异步通知” is broad and maps to a common user request, so an agent could invoke this skill automatically in ordinary payment-debugging conversations without the user explicitly consenting to use this third-party relay service. In this skill’s context, auto-invocation is more dangerous because using the skill causes registration against an external server and routes raw Alipay callback data through a cloud relay, creating unexpected data exposure and network side effects.
