feishu

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Feishu integration skill is broadly coherent with its stated purpose: it enables sending messages, listing chats, and uploading Markdown to Feishu cloud docs, all via a controlled run.py wrapper. Risks primarily center on credential handling, data flow to Feishu services, and potential misconfiguration when uploading local content. There are no explicit download/execution or third-party binary installation patterns, and no obvious exfiltration channels beyond standard Feishu API usage. Overall, the footprint is proportionate to the stated purpose, with moderate security considerations around credentials, data handling, and explicit user consent for actions involving local files.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 02:29 PM
Package URL
pkg:socket/skills-sh/dreasky%2Ffeishu-skill%2Ffeishu%2F@809cef16c7b13884586de70e3988ebfb8c60184d