feishu-im

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is largely consistent with its stated purpose: it provides Feishu IM automation capabilities via well-defined official API endpoints and a Bearer token-based authentication flow. The footprint appears proportionate for a chat administration tool, with no download/install or credential harvesting patterns observed. The main concerns are around credential handling (secure storage/rotation) and ensuring least-privilege permission configuration, given the breadth of granted permissions. Overall, the skill is BENIGN with elevated risk due to its broad access surface (securityRisk ~ 0.4; malware ~ 0.15).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 04:55 PM
Package URL
pkg:socket/skills-sh/alextangson%2Ffeishu_skills%2Ffeishu-im%2F@bc7440d6b146d236c8920add91c717e23613dfbf