feishu-cli-toolkit

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's Feishu-focused capabilities are largely aligned with its stated purpose, but its core dependency is a personally published external CLI installed via raw GitHub `curl|bash` and unsigned release binaries. Because the skill also directs tokens and sensitive workspace content through that binary, the install-trust and credential-forwarding risks are disproportionate enough to classify it as suspicious rather than benign.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Apr 24, 2026, 12:54 PM
Package URL
pkg:socket/skills-sh/riba2534%2Ffeishu-cli%2Ffeishu-cli-toolkit%2F@9779459c61954974beb6bf170684f42cb4b50924