Back to skill

Security audit

Feishu Task Suite

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Feishu task-management helper; its main caution is that broad task-related trigger words could activate it when the user only mentions tasks generally.

Install this if you want your agent to manage Feishu tasks. Because it can create, list, update, delete, complete, and share tasks or task lists under your Feishu identity, confirm the target task/list and members before allowing changes, especially when you only mentioned tasks in a generic way.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger conditions are broad enough to activate on common mentions of '任务', '待办', 'to-do', or 'task' even when the user is not explicitly asking to use Feishu. In an agent setting, this can cause unintended tool invocation against a real task-management account, leading to accidental creation, modification, or disclosure of task data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.