feishu-cli-chat

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s capabilities largely match its stated Feishu chat-management purpose, and the described data flow is mainly to Feishu APIs. Risk comes from relying on a personal third-party CLI for core auth/API access, forwarding sensitive tokens to that CLI, and exposing destructive chat-management actions plus Bash/Write while processing untrusted chat content. Overall this is better classified as suspicious/high-vulnerability than benign, but not confirmed malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 15, 2026, 07:31 AM
Package URL
pkg:socket/skills-sh/riba2534%2Ffeishu-cli%2Ffeishu-cli-chat%2F@a97e9db2b9955204a6e4310c669276578e2b0411