Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The README includes concrete bot credential fields (`appId`, `appSecret`), user identifiers (`open_id`, `allowFrom`), and private-message routing examples, but does not warn readers not to commit real secrets or expose user identifiers. In a messaging integration skill, this omission can lead operators to paste production tokens and personal IDs into configs, docs, or repos, causing credential leakage and privacy exposure.
