feishu-sticker
Pass
Audited by Gen Agent Trust Hub on Feb 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
- [EXTERNAL_DOWNLOADS] (SAFE): The skill utilizes
ffmpeg-static, which downloads an external binary at install time. This is standard for its intended purpose of GIF-to-WebP conversion as described in the documentation.\n- [NO_CODE] (SAFE): The main scriptsend.jsand several listed dependencies (axios,form-data) are missing from the package. This limits the scope of the analysis to the auxiliary search functionality infind.js.\n- [DATA_EXPOSURE] (SAFE): A hardcoded system path infind.js(/home/crishaocredits/...) exposes a local username. This is a low-risk information disclosure of an environment-specific default.
Audit Metadata