Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The guide explicitly recommends bypassing Feishu pairing approval by setting `dmPolicy: "open"` and `allowFrom: ["*"]`, which removes an access-control step for direct messages. In a bot deployment context, this can expose the agent to unsolicited interaction, spam, prompt-injection attempts, and unintended data disclosure if the bot responds to untrusted users.
