Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to persist sensitive WeCom bot credentials (`botId` and `secret`) into a local config file and restart the gateway, but it provides no user-facing consent step, no warning about credential storage, and no guidance on protecting the file. This is dangerous because it causes a security-sensitive system change and secret persistence on the host, increasing the risk of accidental exposure, misuse by other local processes, or unexpected service disruption from the restart.
