Feishu Integration Developer

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill demonstrates best practices for credential management by requiring the use of environment variables for sensitive information such as FEISHU_APP_ID and FEISHU_APP_SECRET, explicitly advising against hardcoding them.
  • [SAFE]: All external code references and dependencies target the official Lark/Feishu Open Platform SDK (@larksuiteoapi/node-sdk), which is a well-known and trusted service for this domain.
  • [SAFE]: The skill includes specific instructions for event signature verification and payload decryption, which are critical security measures for Feishu Event Subscriptions.
  • [SAFE]: All network operations are directed towards official Feishu API endpoints (open.feishu.cn), with no evidence of unauthorized data exfiltration or suspicious remote calls.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 02:36 PM
Security Audit — agent-trust-hub — Feishu Integration Developer