feishu-wiki

Fail

Audited by Socket on Mar 25, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/add_records.py

This script is a legitimate automation for uploading job records to a Feishu Bitable table. It does not contain typical malware constructs (no reverse shell, no obfuscated payloads, no unknown-network exfiltration). The primary security issue is plaintext hardcoded credentials and tokens — a significant supply-chain/credential leak risk. Treat embedded secrets as compromised, remove them from source, and rotate credentials. Improve input validation and error handling to reduce privacy and operational risks.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 25, 2026, 03:08 PM
Package URL
pkg:socket/skills-sh/zephyrwang6%2Fmyskill%2Ffeishu-wiki%2F@fc330063806508664f411e722931160aa3504fb1