Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill advertises itself as searching a configured Feishu document space, but its documented behavior can forward user questions to another bot/person and external technical space. This creates an undocumented data-flow expansion: user prompts and possibly sensitive business questions may be transmitted outside the configured scope, violating least privilege and user expectations.
