Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The script embeds a live WeCom webhook secret directly in source code, which is effectively a credential for posting to an external corporate channel. Anyone with access to the code can reuse that webhook to send arbitrary messages, spam the channel, or abuse it as an exfiltration endpoint, and the skill’s purpose of automated outbound posting makes this more dangerous rather than less.
