feishui-file-sender

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill does what it says: it helps send a chosen local file or zip archive to Feishu, with the main risk being accidental disclosure if used carelessly.

Install this only if you want the agent to send selected files through your configured Feishu account. Before using it, verify the exact file or archive contents, confirm the Feishu chat or user ID, and avoid sending secrets, credentials, broad workspace folders, or proprietary/private data unless that disclosure is intended.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly instructs users to package and transmit arbitrary local files or directories to a Feishu target, but it provides no warning to verify archive contents or avoid secrets, credentials, private data, or proprietary code. In this context, the skill operates on workspace content and absolute file paths, so a user could easily exfiltrate sensitive material to an external chat by mistake, making the omission security-relevant rather than purely informational.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal