feishu-cli-work
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation references the author's GitHub repository (github.com/riba2534/feishu-cli) for installation of the required feishu-cli tool. This is a legitimate reference to the vendor's own resource and follows standard tool-based workflow documentation patterns.
- [SAFE]: The skill mentions local configuration files such as
~/.feishu-cli/token.jsonand~/.feishu-cli/config.yamlto explain the tool's internal authentication logic. The instructions do not direct the AI agent to read these files directly or exfiltrate their contents. - [SAFE]: Execution rules in
SKILL.mdmandate that the agent must display target and key parameters for human review before performing any actions that modify data (e.g., creating, updating, or deleting calendar events and tasks). This provides a necessary layer of oversight for automated workplace management.
Audit Metadata