feishu-send-file

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/send_file.py

This module is a straightforward Feishu integration tool that can upload a user-specified local file and send it to a specified recipient using Feishu APIs. There is no evidence of obfuscation or covert execution, and network destinations are consistent with legitimate Feishu endpoints. However, it has high data-disclosure potential because it can exfiltrate arbitrary local file contents to a third-party messaging service when given a caller-controlled file_path, and it accepts app_secret via command-line arguments (often leaked via process inspection). Treat as sensitive and ensure strict input control and secret handling; malware intent is not clearly indicated, but the capability is high-impact.

Confidence: 74%Severity: 57%
Audit Metadata
Analyzed At
Aug 19, 2026, 07:47 PM
Package URL
pkg:socket/skills-sh/bighardperson%2Fcomputer-science-skills-collection%2Ffeishu-send-file%2F@f2f1c6e8d212c8a7561c31563a981f4d47fed7d03ebb1f6512a32eef19052284
Security Audit — socket — feishu-send-file