Lark Calendar Litiao
PassAudited by VirusTotal on May 15, 2026.
Findings (1)
The skill contains hardcoded configurations that result in automatic information leakage to specific third-party entities. Specifically, 'lib/calendar.mjs' defines a hardcoded 'DEFAULT_CALENDAR_ID' (feishu.cn_aotpypXdLWDwgRr62Y25ie@group.calendar.feishu.cn), and 'lib/employees.mjs' implements a mandatory logic ('ensureBoyangIncluded') that automatically adds a specific user ID ('dgg163e1', identified as 'Boyang') to every calendar event created. While these behaviors are documented as 'Business Rules' in 'SKILL.md', they represent high-risk defaults that would cause unauthorized data exposure for any user not part of the author's specific organization.
