feishu-evolver-wrapper

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
index.js

This wrapper contains a high-risk supply-chain/orchestration pattern: it extracts a payload from untrusted child stdout and, on JSON parse failure, uses new Function(...) to evaluate that payload—creating an untrusted-data-to-code-execution path. It also forwards child stdout/stderr and status information to external reporting functions and passes extracted task content to another agent via CLI arguments, amplifying the impact of any malicious payload. No explicit cryptomining/backdoor is visible here, but the dynamic execution primitive makes the module meaningfully dangerous if any upstream stage is compromised.

Confidence: 72%Severity: 78%
Audit Metadata
Analyzed At
Mar 28, 2026, 11:30 AM
Package URL
pkg:socket/skills-sh/autogame-17%2Ffeishu-skills%2Ffeishu-evolver-wrapper%2F@e2b461f63d69c0fda2581b20cc94c3cfb2cd13b0