Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- This sink is explicitly designed to transmit parsed document content to Feishu/Lark, which extends the skill from local parsing into third-party publication/storage. That creates a real data-exfiltration and scope-expansion risk, especially if users invoke the skill expecting only local conversion based on the manifest’s parsing-focused description.
