Feishu Cli Board

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a normal Feishu whiteboard helper, but it can create or change Feishu documents using configured app credentials.

Install this only if you want an agent to operate Feishu whiteboards. Use a trusted feishu-cli installation, least-privilege Feishu app credentials, and confirm document or whiteboard IDs before running commands, especially for generic requests like drawing or visualization.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill declares very broad trigger phrases such as '画个图', '可视化', and '节点图', which can match many ordinary user intents and cause the agent to invoke this skill unexpectedly. Because the skill is user-invocable and has Bash/Read/Write tool access plus integration with authenticated Feishu APIs, over-triggering increases the chance of unnecessary file creation, document modification, or use of stored credentials in contexts the user did not intend.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal