Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the bot/workflow to download message attachments, persist files into Feishu cloud docs, write metadata into a table, and post status messages, but it does not require any user-facing notice, consent gate, or data-handling disclosure before those side effects occur. Because inputs originate from chat messages and may contain private papers, copyrighted PDFs, personal metadata, or sensitive links, silent persistence and redistribution can create privacy, compliance, and data-retention risks.
