feishu-doc-perm

Fail

Audited by Snyk on Mar 8, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). 该技能明确要求从文档 URL/返回值提取文档 Token 并把 token 作为命令行参数(例如 feishu_perm ... token=xxx)嵌入命令/示例,迫使模型处理并可能输出敏感令牌的明文值,属于高风险暴露。
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 8, 2026, 02:24 AM