Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly tells the user to paste a Feishu App ID and App Secret into chat, creating a direct credential collection path. Even if intended for setup convenience, collecting secrets through conversational channels increases the risk of disclosure via logs, model retention, transcript sharing, or misuse by the agent.
