feishu-send-file

Fail

Audited by Snyk on Mar 9, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The prompt contains examples and usage patterns that embed secrets verbatim (app_id/app_secret) in curl request bodies and as CLI arguments (e.g., ./scripts/send-file.sh <app_id> <app_secret> and the tenant_access_token curl -d with app_secret), so an agent generating those commands would need to output secret values directly, creating exfiltration risk despite recommending env vars.
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 9, 2026, 03:57 PM