飞书群学习分析
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill contains hardcoded sensitive credentials (app_id and app_secret) and specific target Chat IDs in both `analyze.sh` and `group_learning.py`. While the logic performs the stated task of Feishu message analysis, hardcoding secrets is a critical security vulnerability, and the use of specific, pre-defined chat IDs (e.g., '养虾乐园') suggests the code is not generalized for safe public use. No evidence of intentional data exfiltration to a third party was found, but the credential exposure is high-risk.
