Vague Triggers
Medium
- Confidence
- 91% confidence
- Finding
- The trigger list is overly broad for a network-capable skill and includes common terms such as '消息', '通知', and '群消息', which can cause the skill to activate in ordinary conversations unrelated to Feishu webhook delivery. In context, unintended invocation is more dangerous because the skill is designed to send outbound messages to an external webhook, increasing the chance of accidental data disclosure or unintended message posting.
