Vague Triggers
Medium
- Confidence
- 82% confidence
- Finding
- The skill advertises that voice messages are 'automatically triggered' for transcription with broad file-type matching and no visible scoping, consent, or activation boundaries. In an agent environment, this can cause unintended processing of user content, surprise execution on untrusted attachments, and privacy exposure if sensitive audio is transcribed without explicit opt-in.
