Feishu Daily Report

Security checks across malware telemetry and agentic risk

Overview

This skill is a local report generator that reads user-provided work data and produces Markdown, with no evidence of hidden network sending or credential use.

Reasonable to install for local report generation. Treat any future use that actually sends reports to Feishu, chat, email, or another destination as a separate permission decision: confirm the destination, schedule, and content before enabling automated delivery.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The phrase indicating automatic sending lacks limits on destination, timing, authorization, and confirmation, making the trigger condition under-specified. If integrated into an automation-capable agent, this ambiguity could lead to unsanctioned distribution of reports to the wrong channel or at the wrong time, creating confidentiality and operational risks.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The phrase indicating automatic sending lacks limits on destination, timing, authorization, and confirmation, making the trigger condition under-specified. If integrated into an automation-capable agent, this ambiguity could lead to unsanctioned distribution of reports to the wrong channel or at the wrong time, creating confidentiality and operational risks.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal