feishu-im
Fail
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill is largely consistent with its stated purpose: it provides Feishu IM automation capabilities via well-defined official API endpoints and a Bearer token-based authentication flow. The footprint appears proportionate for a chat administration tool, with no download/install or credential harvesting patterns observed. The main concerns are around credential handling (secure storage/rotation) and ensuring least-privilege permission configuration, given the breadth of granted permissions. Overall, the skill is BENIGN with elevated risk due to its broad access surface (securityRisk ~ 0.4; malware ~ 0.15).
Confidence: 98%
Audit Metadata