Intent-Code Divergence
Medium
- Confidence
- 90% confidence
- Finding
- The script is presented as a general-purpose upload utility, but it reads a persistent Feishu access token from disk and then prints part of that bearer token to stdout. Even partial token disclosure is sensitive because logs, terminal history capture, screen sharing, or monitoring systems may expose credentials to unauthorized viewers.
