Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs users to package and transmit arbitrary local files or directories to a Feishu target, but it provides no warning to verify archive contents or avoid secrets, credentials, private data, or proprietary code. In this context, the skill operates on workspace content and absolute file paths, so a user could easily exfiltrate sensitive material to an external chat by mistake, making the omission security-relevant rather than purely informational.
