Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The scheduled-task examples instruct users to place message bodies, recipient identifiers, and the webhook key directly into cron/job definitions without warning that those values will be transmitted to the external WeCom webhook endpoint. In practice, this can cause unintended disclosure of sensitive operational content and contact identifiers, especially because scheduled jobs are often reused, logged, or inspected by other operators.
