Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to delete a local file and make authenticated network requests to a third-party Feishu endpoint while storing session cookies in /tmp, but it does not require any user notice or consent before doing so. This creates privacy and operational risk because registration/session data may be transmitted or left temporarily accessible on disk, and the user is not informed that the agent is initiating an external registration flow on their behalf.
