feishu-automation

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is largely coherent with its stated purpose of Feishu automation via lark-mcp. It relies on official Feishu API endpoints and standard token-based authentication, which is appropriate for its domain. However, there are potential security concerns around credential handling and token exposure in the documentation and sample code. No evidence of malicious intent (no unverifiable binaries, no data exfiltration beyond Feishu APIs, and no autonomous dangerous actions) is found. Overall risk is moderate due to token handling patterns; ensure secrets are never logged and are stored/rotated securely, and sanitize sample code to avoid printing tokens in logs.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 02:36 PM
Package URL
pkg:socket/skills-sh/aaaaqwq%2Fagi-super-skills%2Ffeishu-automation%2F@af4c41c73eab35c5c76dad97282edfeed078bd6c