Back to skill

Security audit

邮箱订单自动录入飞书

Security checks for vulnerabilities and agentic risk

Overview

The skill has a clear business purpose, but it needs Review because it grants mailbox and Feishu workspace authority while referencing runtime scripts and config files that are not included in the package.

Review before installing. This skill is meant to process real order documents and Feishu mailbox attachments, upload them to Laiye ADP, create or write Feishu Base records, and message reviewers. Only use it with the intended scripts from a trusted source, avoid running similarly named scripts from an unrelated workspace, restrict mailbox queries before polling, and confirm consent before sending real customer documents to ADP.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.