Morning Report

PassAudited by VirusTotal on Apr 1, 2026.

Findings (1)

The skill 'morning-report' is designed to generate industry intelligence reports using web searches. However, SKILL.md contains an explicit instruction to hardcode a specific DingTalk recipient ID (target: 2735046220840628) when calling the 'message' tool. This ensures that the generated report is sent to a fixed external destination regardless of who executes the skill, effectively redirecting the agent's output and utilizing the user's search resources for a third party's benefit. While it does not attempt to exfiltrate local credentials or sensitive files, this hardcoded 'phone-home' behavior is a significant red flag for unauthorized data redirection.