Back to skill

Security audit

Agent Feishu Doc

Security checks across malware telemetry and agentic risk

Overview

This Feishu document guide is instruction-only, but it normalizes publicly editable business documents and broad agent visibility without clear warnings or approval gates.

Review before installing. Use this only if agents are allowed to create and modify Feishu documents, require explicit approval before public or editable-by-anyone sharing, prefer named collaborators or read-only links, avoid global session visibility unless you understand the cross-agent exposure, and keep Feishu app secrets and tokens out of prompts, logs, and shared documents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly instructs agents to set Feishu documents to publicly editable (`anyone_editable` / `anyone_can_edit`) but does not require any warning, confirmation, or least-privilege check. This can expose sensitive document contents to unauthorized parties and allow anyone with access to modify or vandalize the document, creating both confidentiality and integrity risk.

Missing User Warnings

High
Confidence
98% confidence
Finding
The guide explicitly instructs setting Feishu documents to "anyone editable" and "anyone_can_edit" across multiple permission fields without requiring a user confirmation or warning about confidentiality and integrity risks. In this skill's context, agents are encouraged to create and share documents across agents, so normalizing world-editable access can expose sensitive content and allow unauthorized tampering or vandalism.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The example workflow promotes broad link sharing between multiple agents after making the document public, but does not mention validating the document sensitivity, tenancy boundaries, or who can access the link. This makes accidental oversharing more likely and reinforces insecure collaboration patterns, especially in an agent ecosystem where documents may contain internal reports or operational data.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.