Context-Inappropriate Capability
Medium
- Confidence
- 87% confidence
- Finding
- The skill includes Feishu file transmission commands, which extend beyond local PPT generation into outbound data transfer. In an agent context, any built-in messaging capability can be abused to exfiltrate generated presentations or embedded source material to external recipients, especially if recipient IDs or file paths are supplied without strict validation and user confirmation.
