dot-skill

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
tools/feishu_mcp_client.py

No clear malicious payload is present within this Python snippet itself. The primary concerns are (1) supply-chain/execution risk from running `npx -y feishu-mcp` at runtime (dynamic resolution/installation/execution) and (2) plaintext storage of high-value Feishu credentials in a predictable file under the user’s home directory, plus (3) passing those secrets to a child process via environment variables and (4) writing fetched content to an arbitrary user-specified output path.

Confidence: 70%Severity: 65%
Audit Metadata
Analyzed At
May 5, 2026, 04:16 AM
Package URL
pkg:socket/skills-sh/titanwings%2Fcolleague-skill%2Fcreate-colleague%2F@3c77748ba0800a94c7cb021e07e69ef6aa0528e3