Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill instructs the user to retrieve and use an App Secret, but does not give strong handling guidance such as never pasting it into chat, storing it only in protected configuration, or rotating it if exposed. In an agent setting, this omission can lead users to disclose a live credential in conversation history or unsafe files, enabling unauthorized access to the Feishu integration.
