Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The README explicitly describes sending message content to an external WeCom webhook but does not warn users that provided content leaves the local environment and is transmitted to a third-party service. In an agent skill context, this can lead to accidental disclosure of prompts, secrets, personal data, or internal business information if users or upstream agents pass sensitive content into the tool.
