Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs the agent/user to read Feishu appId and appSecret from a local configuration file using grep, which expands the skill from sending files into harvesting secrets from the host. In an agent environment with broad file access, this creates a clear path to retrieve sensitive credentials and then use them for outbound API actions, increasing the risk of credential exposure and misuse.
