Back to skill

Security audit

WeChat to Feishu Wiki

Security checks across malware telemetry and agentic risk

Overview

This is a clearly scoped Feishu Wiki archiving skill, but users should verify the target wiki before letting it create pages.

Install only if you intend to let the agent create pages in Feishu. Provide the exact target Wiki link, grant the Feishu bot the minimum edit permission needed, review the destination before bulk imports, and use Chrome-based extraction only when normal web fetching does not capture the article content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill performs a remote write operation to a user-provided Feishu Wiki and explicitly instructs creation of pages and document writes, but it does not require an explicit confirmation step immediately before modifying the destination. This creates a real safety issue because a mistaken, maliciously supplied, or misunderstood wiki link could cause unintended data creation or overwriting in an external system.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.