feishu-bridge

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the code fragment describes a coherent Feishu-to-ThinkFleet bridge with local secret handling and macOS auto-start support. There is no clear indication of data exfiltration, credential harvesting, or remote code execution. As such, the footprint is primarily benign but carries typical supply-chain and runtime security considerations around secret storage, explicit environment/config dependencies, and explicit network endpoints. Recommend ensuring secret files are tightly protected, endpoints are authenticated and authenticated tokens are not logged, and that auto-start components cannot be manipulated by non-privileged users.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:14 AM
Package URL
pkg:socket/skills-sh/ThinkfleetAI%2Fthinkfleet-engine%2Ffeishu-bridge%2F@9e50d1ed8e38c83232080987d45baa22780b069f