feishu-cli-messaging

Fail

Audited by Snyk on Jul 31, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). Contains a third‑party GitHub repo referenced as the installation source for a CLI (https://github.com/riba2534/feishu-cli) — downloading/executing software from individual/unvetted repos is a higher risk than using official vendor channels.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). 源自《飞书会话浏览与管理》的运行路径会通过 scripts/fetch_chat_history.py 调用 feishu-cli msg history/msg thread-messages/msg get 等读取群聊消息正文与嵌入卡片内容(用户在群里可自由发言/提交文本)。

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 31, 2026, 11:15 AM
Issues
2
Security Audit — snyk — feishu-cli-messaging