feishu-cli-read
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The read-only Feishu purpose is coherent, but the skill relies on a non-official third-party CLI that can automatically read local token files and handle authenticated API access outside the skill. The main concern is install/execution trust and credential forwarding to external code, not obvious malicious exfiltration.
Confidence: 80%Severity: 72%
Audit Metadata