feishu-cli-meetings

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation (references/workflows/vc/workflow.md) directs users to download the 'feishu-cli' tool from the author's GitHub repository at https://github.com/riba2534/feishu-cli. This is a legitimate vendor resource used to provide the skill's core functionality.
  • [COMMAND_EXECUTION]: The skill executes 'feishu-cli' commands through a Bash shell to interact with Feishu APIs. Execution is scoped to the 'feishu-cli' namespace as defined in the 'allowed-tools' metadata.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of meeting transcripts and AI-generated summaries via ingestion points like 'feishu-cli vc notes' and 'feishu-cli minutes get'. While there are no explicit boundary markers or sanitization steps mentioned for this external content, the capability is restricted to file writing and specific CLI operations, and the data processing is central to the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 11:15 AM
Security Audit — agent-trust-hub — feishu-cli-meetings