Feishu Integration Developer
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill demonstrates best practices for credential management by requiring the use of environment variables for sensitive information such as
FEISHU_APP_IDandFEISHU_APP_SECRET, explicitly advising against hardcoding them. - [SAFE]: All external code references and dependencies target the official Lark/Feishu Open Platform SDK (
@larksuiteoapi/node-sdk), which is a well-known and trusted service for this domain. - [SAFE]: The skill includes specific instructions for event signature verification and payload decryption, which are critical security measures for Feishu Event Subscriptions.
- [SAFE]: All network operations are directed towards official Feishu API endpoints (
open.feishu.cn), with no evidence of unauthorized data exfiltration or suspicious remote calls.
Audit Metadata