Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The README explicitly describes automatic delivery of generated content through external messaging channels such as Enterprise WeChat or QQ, but provides no warning, consent flow, or controls around outbound transmission. In a scheduled skill, this can cause unintended disclosure of generated summaries, prompts, or sensitive contextual data to third-party services, especially if the skill later incorporates private sources or user data.
