Back to skill

Security audit

Feishu Doc

Security checks across malware telemetry and agentic risk

Overview

This is a simple Feishu document skill whose disclosed read and write abilities match its stated purpose.

Install this if you want an agent to use your Feishu permissions to read and change documents. For important or shared documents, confirm the exact target document and intended change before allowing create, update, or append actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly supports creating, updating, and appending Feishu documents, but it does not clearly warn users that invoking it may modify external documents and persist changes. This can lead to unintended data alteration, overwrite, or creation of documents when a user expected read-only behavior, especially in an agent setting where tool invocation may be implicit.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.