feishu-calendar-advanced

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The purpose and requested Feishu credentials are coherent for calendar management, but the skill's main risk is trust delegation to an unpinned third-party CLI run via `bunx`. There is no clear evidence of outright malware or off-purpose behavior, yet credential forwarding and opaque network handling inside externally fetched code make this a medium-to-high security risk.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Aug 19, 2026, 07:47 PM
Package URL
pkg:socket/skills-sh/bighardperson%2Fcomputer-science-skills-collection%2Ffeishu-calendar-advanced%2F@dd4bcf300d73a5b4c6791ab7bb27744d6612d7d9ebc7fc82cc6a2cc49aa951f4
Security Audit — socket — feishu-calendar-advanced