feishu-notify

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The "Interactive" mode (Step 3) uses curl to poll an external bridge_url for a user's reply, which is then returned to the agent's context. An attacker with control over the bridge server or the Feishu account could provide malicious instructions within the reply to influence the agent's subsequent actions.
  • Ingestion points: SKILL.md instructions for Step 3 execute curl -s "$BRIDGE_URL/poll" to fetch external content.
  • Boundary markers: No delimiters or instructions are provided to the agent to treat the external reply as untrusted data or to ignore embedded commands.
  • Capability inventory: The skill itself uses Bash(curl *) and Bash(cat *). The calling skills (e.g., /auto-review-loop, /research-pipeline) likely possess significant capabilities, such as file system modifications or complex command execution, which could be abused via injected instructions.
  • Sanitization: There is no evidence of sanitization, validation, or filtering of the response received from the bridge URL before it is processed by the agent.
  • [EXTERNAL_DOWNLOADS]: The skill documentation references a requirement for an external, third-party bridge server hosted at an untrusted GitHub repository (github.com/joewongjc/feishu-claude-code). While the skill does not automatically install this dependency, the instructions direct the user to run unverified code to enable core functionality, posing a supply chain risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:07 PM
Security Audit — agent-trust-hub — feishu-notify