feishu-card

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
handle_event.js

This module is not obviously malicious on its own, but it contains a high-risk command injection vulnerability: untrusted values (userOpenId and menuKey) are interpolated into a shell command executed via child_process.execSync, allowing an attacker controlling eventPayload to execute arbitrary commands. The primary risk is remote command execution on the host. Recommend replacing execSync usage with execFile/spawn and strict input validation/escaping, and avoid logging entire payloads in production.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:38 AM
Package URL
pkg:socket/skills-sh/ypyt1%2Fall-skills%2Ffeishu-card%2F@23fe485e972625c5b3a0434e3e9165acd6361ef2