feishu-docs

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Feishu Docs CLI skill is largely coherent with its stated purpose and generally uses appropriate authentication and API-driven data flows. The footprint is proportionate (no obvious unverifiable binaries or external credential forwarding beyond the intended Feishu API usage). However, credential handling requires careful secret management (env vars, login tokens, and backups) to prevent leakage, and explicit security measures around logging and token handling are not described. The local backups feature is sensible but introduces potential data-at-rest concerns without encryption or access control details. Overall, the stance is BENIGN with notable security-conscious caveats; treat as SUSPICIOUS if credentials are stored insecurely, logged in plaintext, or if the distribution/source of the feishu-docs CLI cannot be trusted or verified.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 03:35 PM
Package URL
pkg:socket/skills-sh/cliff-byte%2Ffeishu-docs-cli%2Ffeishu-docs%2F@e88111d348968ce36187ea09545904304901ae50