Missing User Warnings
Medium
- Confidence
- 85% confidence
- Finding
- The documentation explicitly enables `allowDM: true` but does not warn that direct messages expand the bot's message scope beyond controlled servers, which can expose private conversations, increase phishing/social-engineering surface, and bypass guild-based access restrictions. In this context, the risk is real because the same document otherwise encourages restricting usage to trusted guild IDs, so presenting DM support without corresponding privacy and authorization guidance can lead to unsafe deployment.
