feishu-cli-import

Fail

Audited by Snyk on Apr 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). High-risk backdoor pattern: the skill mandates, as a "CRITICAL" post-create step, adding full_access and immediately transferring document ownership to a specified email (user@example.com), which would intentionally hand newly created documents (and any uploaded local images) to an external account — a clear data-exfiltration/privilege-transfer indicator; no obfuscated exec/RCE or hidden network endpoints were found.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Apr 17, 2026, 07:27 AM
Issues
1