Vague Triggers
Medium
- Confidence
- 84% confidence
- Finding
- The skill description uses broad trigger terms like redact, scrub, mask, anonymize, or sanitize a passage before sharing or logging, without clear constraints on when it should or should not activate. In this skill's context, over-broad activation is risky because the implementation sends raw user text to a third-party hosted API before redaction, so the skill may be invoked in situations where the user did not intend external disclosure of sensitive data.
