feishu-cli-export

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

结论为 SUSPICIOUS。技能用途与导出能力大体匹配,也未见明确恶意外传端点;但它把飞书应用凭证与用户 Token 交给个人开发者发布的第三方 CLI,并依赖 raw GitHub 的 curl|bash 安装与可变版本发布,构成显著供应链与凭证转交风险。

Confidence: 85%Severity: 84%
Audit Metadata
Analyzed At
Apr 27, 2026, 03:06 AM
Package URL
pkg:socket/skills-sh/riba2534%2Ffeishu-cli%2Ffeishu-cli-export%2F@44ca509d803b1dedb4b138d20de3d671d30531d5