feishu-cli-chat
Warn
Audited by Socket on May 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill’s capabilities largely match its stated Feishu chat-management purpose, and the described data flow is mainly to Feishu APIs. Risk comes from relying on a personal third-party CLI for core auth/API access, forwarding sensitive tokens to that CLI, and exposing destructive chat-management actions plus Bash/Write while processing untrusted chat content. Overall this is better classified as suspicious/high-vulnerability than benign, but not confirmed malware.
Confidence: 84%Severity: 58%
Audit Metadata