Back to skill

Security audit

Feishu Workflow CLI

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate Feishu/Lark workflow guide, but it gives agents broad authority to send messages, email, alter work records, and join or monitor meetings without strong enough confirmation and privacy gates.

Install only if you want an agent to operate authenticated Feishu/Lark workflows. Require explicit confirmation before any send, share, meeting join, meeting monitor, approval, record update, or external email; verify recipients and link permissions; and avoid confidential meetings or reports unless your organization has approved those automation controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
81% confidence
Finding
The skill explicitly states that cross-platform workflows should be delegated, yet provides an inline executable DingTalk command. In an agent setting, this inconsistency can cause the agent to directly invoke an unintended external platform, expanding the action surface and risking unauthorized or misrouted communications.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.