Description-Behavior Mismatch
High
- Confidence
- 97% confidence
- Finding
- The skill is declared as export-only, but the documented "doc import-file" workflow adds a separate capability to upload local files into Feishu. That scope expansion can cause an agent to perform unintended data transfer from the local machine to a remote SaaS, which is materially riskier than a read/export operation and may violate user intent or data handling expectations.
