feishu-messages

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its described purpose: it reads credentials and target identifiers from CLI, authenticates against Feishu, retrieves messages via the official API, and outputs results. Data flows are source-to-endpoint (Feishu API) and then to stdout. The main security considerations are proper handling of App Secret (avoid logging it) and ensuring users understand that credentials may be exposed in process logs or stdout if not redacted. Overall, benign with moderate risk due to credential handling in CLI contexts.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 07:53 AM
Package URL
pkg:socket/skills-sh/blankPen%2Fskills%2Ffeishu-messages%2F@f451c54fcec035e138219fe3ffa6b2636b06d1c3