Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The documentation explicitly shows generating a QR code and sending it via Feishu, but it does not warn that QR payloads may encode sensitive data such as login URLs, access tokens, WiFi credentials, or internal links. This can normalize unsafe sharing practices and lead users to transmit secrets through chat platforms or leave sensitive QR images on disk where they may be exposed.
