Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill is designed to ingest communication records from Feishu docs, meeting minutes, and pasted text, which commonly contain sensitive business and personal data, yet it provides no user-facing notice, consent checkpoint, or data-handling boundary. This creates a privacy and unauthorized-processing risk because users may trigger collection, summarization, and onward document generation without understanding what data will be accessed or exposed.
