feishu-calendar-advanced
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The purpose and requested Feishu credentials are coherent for calendar management, but the skill's main risk is trust delegation to an unpinned third-party CLI run via `bunx`. There is no clear evidence of outright malware or off-purpose behavior, yet credential forwarding and opaque network handling inside externally fetched code make this a medium-to-high security risk.
Confidence: 84%Severity: 72%
Audit Metadata