Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The README includes concrete Feishu authentication and message-delivery code even though the skill is described as spec-only and explicitly not for directly sending Feishu messages. In an agent-skill context, this can cause downstream agents or users to treat the skill as authorized to exfiltrate generated content to an external service, expanding capability beyond the declared trust boundary.
