feishu-cli-bitable
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute feishu-cli commands for managing Feishu Bitable resources. All commands are consistent with the skill's purpose and use user-provided tokens for authentication.\n- [SAFE]: Indirect Prompt Injection Surface. The skill processes data from Feishu (e.g., in SKILL.md via
feishu-cli bitable record list), which constitutes an ingestion point for untrusted data. No boundary markers or sanitization logic are defined in the instructions. However, the capabilities available to the agent are limited to standard Feishu API operations, and no malicious patterns targeting this surface were detected.\n- [SAFE]: The skill does not contain any obfuscated code, hardcoded credentials, or unauthorized network operations. It uses standard CLI practices for resource management.
Audit Metadata