feishu-drive
Fail
Audited by Snyk on Feb 25, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The skill requires extracting and embedding folder/file tokens (e.g., folder_token, file_token) verbatim into generated JSON actions, so the LLM will output resource tokens it received or parsed, creating an exfiltration risk.
Audit Metadata