Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill shows a configuration example containing a DingTalk webhook URL and secret but does not warn that these are sensitive credentials. Users may copy real values into plaintext config files, screenshots, logs, or source control, which can let others send messages to the robot or abuse the integration.
