feishu-cli-export

Warn

Audited by Socket on May 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS:功能本身与“飞书文档导出”大体一致,且声明的数据终点主要是飞书官方 API 与本地文件;但技能把关键能力建立在个人账号发布的 feishu-cli 之上,并可能通过未固定的 raw GitHub curl|bash 安装,同时将 App Secret 和 User Token 交给该 CLI。发布主体与官方 larksuite/cli 不一致,供应链与凭证转交风险明显高于其声明用途。

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
May 10, 2026, 09:04 AM
Package URL
pkg:socket/skills-sh/riba2534%2Ffeishu-cli%2Ffeishu-cli-export%2F@964fcd246c288d6ea5d613192da0612e47764d31