Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to take user-provided requirements and create Feishu Bitable records, but it does not require a privacy notice, user confirmation of external sharing, or data-minimization before transmission. Because requirements often contain client names, business plans, internal system details, or regulated data, this can cause unintended disclosure to a third-party SaaS workspace.
