feishu-inout

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/feishu_mcp.py

Selected Report 2 as the closest fit. After reviewing the code, there is still no clear evidence of intentional malware (no obfuscation/dynamic execution, no unexpected exfiltration domains, no system-level compromise actions). The primary concerns are security hygiene and abuse potential: plaintext token caching to a fixed path, OAuth callback state not validated, very broad OAuth scopes, and an advanced 'call' path that forwards arbitrary MCP tool names and raw JSON arguments to tools/call.

Confidence: 72%Severity: 50%
Audit Metadata
Analyzed At
Mar 27, 2026, 08:46 AM
Package URL
pkg:socket/skills-sh/joe960913%2Ffeishu-inout%2Ffeishu-inout%2F@879f8c1ba52006fcf71a21f03c67305eda777366