feishu-cli-data
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s purpose and Feishu data-management capabilities are internally coherent, and official same-org evidence exists for the Feishu CLI. The main risk is disproportionate execution trust: it permits wildcard Bash against a local ./feishu-cli binary whose provenance is not verifiable from the skill, creating a supply-chain and credential-forwarding concern even though no direct exfiltration or overtly malicious behavior is shown.
Confidence: 84%Severity: 72%
Audit Metadata