Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The skill goes beyond generating an agent config and explicitly instructs users to set Feishu bot tokens, app secrets, and per-agent account bindings. That expands the skill into credential handling and account orchestration, which increases blast radius and can lead to secret exposure, misbinding of identities, or unauthorized channel access if followed blindly.
