Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill sets up an automated cron job that delivers repository commit data, file-change statistics, and code-review findings to a DingTalk target on an ongoing basis. Even if sent to the intended user, this creates a standing exfiltration path for potentially sensitive internal code metadata without an explicit warning, consent language, or data-minimization controls.
