Back to skill

Security audit

Feishu Doc Block Writer

Security checks across malware telemetry and agentic risk

Overview

This Feishu document-writing skill is purpose-aligned but needs Review because it can automatically upload and create remote documents under broad triggers with limited consent and disclosure.

Install only if you specifically want an agent skill that creates and appends Feishu documents. Before using it, disable or narrow automatic triggering, require confirmation before every Feishu write, verify the missing scripts from a trusted source, choose the destination folder explicitly, and avoid sending secrets, personal data, or regulated content unless the Feishu workspace and account are approved for that data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The auto-trigger conditions are broad enough to activate on ordinary user requests such as asking to create a Feishu document or merely producing a long response. That can cause unintended external data transmission and document creation without a clear, explicit user confirmation at the time of action.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill description emphasizes convenience but does not clearly foreground that user-provided content will be transmitted to Feishu and may be stored in the knowledge base root or another folder. In a skill that handles potentially sensitive text, insufficient disclosure increases the risk of privacy leaks and unintended persistence in external systems.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill is configured with auto_trigger_enabled set to true but does not define any trigger conditions, scope limits, or activation safeguards in the manifest. This can cause the skill to activate broadly and unexpectedly, increasing the chance of unintended document writes or misuse in contexts where Feishu document modification was not explicitly requested.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.