This Feishu skill pack is mostly disclosed and not clearly malicious, but it grants broad Feishu, local file, OAuth, and no-confirmation execution authority that users should review carefully before installing.
Install only if you trust this publisher and are comfortable giving an agent broad Feishu access plus local command execution. Avoid disabling exec confirmations globally, review requested Feishu scopes before approving OAuth, treat local file upload/download/delete and sheet/bitable write operations as sensitive, and be aware that document extraction may install npm packages at runtime.