byted-viking-aisearch-feishu
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary purpose is read-only access to Feishu documents, which is implemented correctly through specific API calls without implementing any write or modification capabilities.
- [SAFE]: Authentication is managed via a standard OAuth provider (
viking_feishu_oauth_provider) and environment variables. The code does not contain hardcoded secrets, and the documentation correctly advises users to use environment variables for sensitive tokens. - [SAFE]: All network operations are restricted to the official Feishu Open Platform domain (
open.feishu.cn). No unauthorized third-party domains or exfiltration patterns were detected. - [SAFE]: No evidence of prompt injection, code obfuscation, or persistence mechanisms was found in the instructions or scripts.
Audit Metadata