feishu-drive

Fail

Audited by Snyk on Feb 25, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The skill requires extracting and embedding folder/file tokens (e.g., folder_token, file_token) verbatim into generated JSON actions, so the LLM will output resource tokens it received or parsed, creating an exfiltration risk.
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 25, 2026, 05:51 AM