feishu-cli-read

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The read-only Feishu purpose is coherent, but the skill relies on a non-official third-party CLI that can automatically read local token files and handle authenticated API access outside the skill. The main concern is install/execution trust and credential forwarding to external code, not obvious malicious exfiltration.

Confidence: 80%Severity: 72%
Audit Metadata
Analyzed At
Apr 11, 2026, 06:26 PM
Package URL
pkg:socket/skills-sh/riba2534%2Ffeishu-cli%2Ffeishu-cli-read%2F@2797fbd1acde06019e09277d0d4f25904bc4e9bd