Back to skill

Security audit

飞书多维表格权限检查

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently checks Feishu document access from a user-provided Bitable and does not contain executable install code, persistence, or hidden behavior.

Before installing, confirm the Bitable and linked documents are appropriate for a batch permission check, use the Feishu account whose access you intend to test, and avoid running or sharing results in contexts where employee names, document links, titles, or access outcomes should remain private.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.