Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill introduces Feishu credentials and message-sending capability that is not clearly justified by the declared purpose. That expands the attack surface to third-party chat delivery and creates a risk of sending user content to external recipients or workspaces without sufficiently prominent disclosure or narrowly scoped authorization.
