feishu-notify
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The "Interactive" mode (Step 3) uses
curlto poll an externalbridge_urlfor a user's reply, which is then returned to the agent's context. An attacker with control over the bridge server or the Feishu account could provide malicious instructions within the reply to influence the agent's subsequent actions. - Ingestion points:
SKILL.mdinstructions for Step 3 executecurl -s "$BRIDGE_URL/poll"to fetch external content. - Boundary markers: No delimiters or instructions are provided to the agent to treat the external reply as untrusted data or to ignore embedded commands.
- Capability inventory: The skill itself uses
Bash(curl *)andBash(cat *). The calling skills (e.g.,/auto-review-loop,/research-pipeline) likely possess significant capabilities, such as file system modifications or complex command execution, which could be abused via injected instructions. - Sanitization: There is no evidence of sanitization, validation, or filtering of the response received from the bridge URL before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill documentation references a requirement for an external, third-party bridge server hosted at an untrusted GitHub repository (
github.com/joewongjc/feishu-claude-code). While the skill does not automatically install this dependency, the instructions direct the user to run unverified code to enable core functionality, posing a supply chain risk.
Audit Metadata