feishu-attendance
Security checks across malware telemetry and agentic risk
Overview
The skill's code mostly matches the described attendance-monitoring purpose, but metadata and instructions omit important credential and dependency details and the code writes outside its folder — these mismatches warrant caution before installing.
This skill's functionality (checking Feishu attendance, holiday lookups, and sending messages) matches its code, but the package metadata omits required credentials and shared dependencies. Before installing: 1) Confirm where the feishu-common and common/time-helper modules come from and inspect them — they will handle authentication and determine what credentials are needed. 2) Expect to provide Feishu app credentials (tenant/app id & secret or tokens); verify which env vars are required and that they are scoped minimally. 3) Note the skill writes cache files to ../../memory/attendance_cache — confirm that path is a safe, intended storage area. 4) Use the --dry-run option first to validate behavior without sending messages. 5) If you cannot review feishu-common or the host environment that supplies shared modules, treat this as higher risk and avoid granting it real credentials or running it with notify enabled.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
