feishu-cli-msg
Warn
Audited by Socket on Apr 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s behavior mostly matches its messaging purpose and data flows appear aimed at Feishu, but it relies on a non-official third-party CLI from a personal GitHub account and can autonomously send real-world communications, including urgent phone/SMS notifications. Main risk is supply-chain trust plus action-taking authority, not clear credential theft or exfiltration.
Confidence: 87%Severity: 58%
Audit Metadata