Storage Manager
PassAudited by VirusTotal on Apr 14, 2026.
Findings (1)
The skill bundle contains hardcoded sensitive credentials, specifically a Feishu App Secret ('HHEZEDoNZwfNdoediXiGSbaRFKDmpB71') and Bitable tokens, across multiple files including complete_system.py, final_integrated.py, and storage_manager_final.py. While these appear to be default or test credentials for a specific Feishu Bitable instance, hardcoding secrets is a critical security vulnerability. Furthermore, the SKILL.md instructions explicitly direct the AI agent to operate 'without user confirmation' for its smart matching logic, which increases the risk of unintended data modification.
