Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill includes code that reads Feishu app credentials from a local config file and immediately exchanges them for a tenant access token over the network, but it does not prominently warn that local secrets are being accessed and transmitted to an external service. In an agent-skill context, this can normalize credential use without explicit user consent and increases the risk of unintended secret handling or unauthorized document access.
