feishu-cli-search

Warn

Audited by Socket on May 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: 目的与搜索能力基本一致,但核心实现依赖非官方个人仓库的 feishu-cli,并将飞书 User Access Token 交由该外部 CLI 管理和使用。数据流看似指向飞书官方 API,但安装与凭证处理信任不足,风险主要来自供应链与第三方凭证转交。

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
May 10, 2026, 09:03 AM
Package URL
pkg:socket/skills-sh/riba2534%2Ffeishu-cli%2Ffeishu-cli-search%2F@de9ecd434d9d6a6829b087fcc866d33c1c916b3b