Feishu Messaging.Bak
飞书消息发送与文档创建工作流。 触发场景:查找群成员、查找群ID、发送消息失败需要重新尝试。 适用于:发送飞书消息。
MIT-0 · Free to use, modify, and redistribute. No attribution required.
⭐ 0 · 19 · 0 current installs · 1 all-time installs
by@make453
fork of @jypjypjypjyp/feishu-messaging (based on 0.0.3)
MIT-0
Security Scan
OpenClaw
Suspicious
high confidencePurpose & Capability
The name, SKILL.md examples and included scripts all implement Feishu (飞书) messaging and user/chat lookup functionality — that is coherent with the stated purpose. However, the skill does not declare any required environment variables in the registry metadata while the bundled JS scripts rely on FEISHU_APP_ID/FEISHU_APP_SECRET (with fallbacks to hard-coded credentials). Additionally _meta.json metadata (owner/slug/version) differs from the registry block, which is unexpected.
Instruction Scope
SKILL.md shows Python examples that expect the developer to supply app_id/app_secret, but it does not mention the included Node.js scripts or the fact that those scripts will read environment variables (FEISHU_APP_ID/FEISHU_APP_SECRET) or fall back to embedded credentials. The runtime instructions do not ask the agent to read unrelated files, but they also do not warn about or explain the embedded secrets or how to replace/revoke them. That lack of transparency widens the skill's effective scope.
Install Mechanism
No install spec is provided and the skill is instruction-only with code files. No external downloads or installers are specified, which is low risk from an installation/mechanism perspective. The presence of executable scripts, however, means running them will execute network calls.
Credentials
The registry requires no environment variables or credentials, but the included scripts expect FEISHU_APP_ID and FEISHU_APP_SECRET (and provide hard-coded fallback values). Hard-coded secrets found in scripts are disproportionate and dangerous: they grant access to a Feishu tenant and are not declared, justified, or documented in the registry metadata or SKILL.md.
Persistence & Privilege
The skill does not request elevated persistence (always: false) and does not attempt to modify other skills or system configuration. Autonomous invocation is enabled by default (disable-model-invocation: false) but that alone is not a high-severity inconsistency here.
Scan Findings in Context
[hardcoded-credentials] unexpected: Multiple JS scripts include embedded APP_ID and APP_SECRET literal strings (e.g. 'cli_a93d0180c0b99cba', 'KJXQ3hqdRerYwyThNq999gL2btUSkOaR'). A messaging integration should request the user to supply credentials or read them from declared env vars; hard-coded secrets are unexpected and risky.
[metadata-mismatch] unexpected: _meta.json contains different ownerId/slug/version than the registry metadata presented. This discrepancy may indicate the bundle was copied or repackaged and the origin is unclear.
What to consider before installing
This skill mostly does what it says (Feishu messaging), but there are important red flags you should address before using it:
- Do not run the included scripts as-is. They contain hard-coded App ID/Secret values that could belong to someone else; running them might send messages or access a tenant you don't control. Treat these as leaked credentials.
- Ask the publisher to confirm the origin and to remove embedded secrets. Prefer a version that requires you to set FEISHU_APP_ID and FEISHU_APP_SECRET explicitly (and documents required scopes and how to obtain/revoke keys).
- If you need this capability, create your own Feishu App credentials, set them via environment variables, and ensure the app only has the minimal permissions (e.g., im:message:send_as_bot, im:chat:readonly) needed.
- Verify and reconcile metadata: the _meta.json owner/slug/version mismatch is suspicious — confirm who published this and why versions differ.
- Consider rotating or revoking any credentials you find embedded here (if they belong to your organization). If you cannot validate the origin and the credentials, avoid installing the skill.
If you want, I can extract the exact lines with hard-coded secrets and produce a sanitized version of the scripts that require explicit env vars and add clear documentation about required permissions and revocation steps.Like a lobster shell, security has layers — review code before you run it.
Current versionv1.0.0
Download ziplatest
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
SKILL.md
飞书消息与文档 Skill
概述
此 Skill 通过飞书开放平台 API 帮助用户发送消息、创建文档和管理飞书资源。
核心能力
| 功能 | 状态 | 所需权限 |
|---|---|---|
| 发送文本消息 | ✅ 可用 | im:message:send_as_bot |
| 获取群聊列表 | ✅ 可用 | im:chat:readonly |
| 获取群成员 | ✅ 可用 | im:chat.members:read |
使用方法
发送消息给指定用户
给 [姓名] 发一条飞书消息,告诉他 [内容]
前置条件:需要获取用户的 open_id
1. 获取群聊id的方法
import json
import lark_oapi as lark
from lark_oapi.api.im.v1 import *
def main():
# 创建client
client = lark.Client.builder() \
.app_id("YOUR_APP_ID") \
.app_secret("YOUR_APP_SECRET") \
.log_level(lark.LogLevel.DEBUG) \
.build()
# 构造请求对象
request: SearchChatRequest = SearchChatRequest.builder() \
.user_id_type("open_id") \
.query("小鸭子") \
.page_size(20) \
.build()
# 发起请求
response: SearchChatResponse = client.im.v1.chat.search(request)
# 处理失败返回
if not response.success():
lark.logger.error(
f"client.im.v1.chat.search failed, code: {response.code}, msg: {response.msg}, log_id: {response.get_log_id()}, resp:
{json.dumps(json.loads(response.raw.content), indent=4, ensure_ascii=False)}")
return
# 处理业务结果
lark.logger.info(lark.JSON.marshal(response.data, indent=4))
if __name__ == "__main__":
main()
2. 发送消息
import json
import lark_oapi as lark
from lark_oapi.api.im.v1 import *
def main():
# 创建client
client = lark.Client.builder() \
.app_id("YOUR_APP_ID") \
.app_secret("YOUR_APP_SECRET") \
.log_level(lark.LogLevel.DEBUG) \
.build()
# 构造请求对象
request: CreateMessageRequest = CreateMessageRequest.builder() \
.receive_id_type("open_id") \
.request_body(CreateMessageRequestBody.builder()
.receive_id("ou_7d8a6e6df7621556ce0d21922b676706ccs")
.msg_type("text")
.content("{\"text\":\"test content\"}")
.uuid("选填,每次调用前请更换,如a0d69e20-1dd1-458b-k525-dfeca4015204")
.build()) \
.build()
# 发起请求
response: CreateMessageResponse = client.im.v1.message.create(request)
# 处理失败返回
if not response.success():
lark.logger.error(
f"client.im.v1.message.create failed, code: {response.code}, msg: {response.msg}, log_id: {response.get_log_id()}, resp:
{json.dumps(json.loads(response.raw.content), indent=4, ensure_ascii=False)}")
return
# 处理业务结果
lark.logger.info(lark.JSON.marshal(response.data, indent=4))
if __name__ == "__main__":
main()
3. 图片消息
import json
import lark_oapi as lark
from lark_oapi.api.im.v1 import *
def main():
# 创建client
client = lark.Client.builder() \
.app_id("YOUR_APP_ID") \
.app_secret("YOUR_APP_SECRET") \
.log_level(lark.LogLevel.DEBUG) \
.build()
# 构造请求对象
file = open("小鸭子.jpg", "rb")
request: CreateImageRequest = CreateImageRequest.builder() \
.request_body(CreateImageRequestBody.builder()
.image_type("message")
.image(file)
.build()) \
.build()
# 发起请求
response: CreateImageResponse = client.im.v1.image.create(request)
# 处理失败返回
if not response.success():
lark.logger.error(
f"client.im.v1.image.create failed, code: {response.code}, msg: {response.msg}, log_id: {response.get_log_id()}, resp:
{json.dumps(json.loads(response.raw.content), indent=4, ensure_ascii=False)}")
return
# 处理业务结果
lark.logger.info(lark.JSON.marshal(response.data, indent=4))
if __name__ == "__main__":
main()
4. 上传文件
import json
import lark_oapi as lark
from lark_oapi.api.im.v1 import *
def main():
# 创建client
client = lark.Client.builder() \
.app_id("YOUR_APP_ID") \
.app_secret("YOUR_APP_SECRET") \
.log_level(lark.LogLevel.DEBUG) \
.build()
# 构造请求对象
file = open("飞书20260129-173520.mp4", "rb")
request: CreateFileRequest = CreateFileRequest.builder() \
.request_body(CreateFileRequestBody.builder()
.file_type("mp4")
.file_name(""1.mp4"")
.duration("3000")
.file(file)
.build()) \
.build()
# 发起请求
response: CreateFileResponse = client.im.v1.file.create(request)
# 处理失败返回
if not response.success():
lark.logger.error(
f"client.im.v1.file.create failed, code: {response.code}, msg: {response.msg}, log_id: {response.get_log_id()}, resp:
{json.dumps(json.loads(response.raw.content), indent=4, ensure_ascii=False)}")
return
# 处理业务结果
lark.logger.info(lark.JSON.marshal(response.data, indent=4))
if __name__ == "__main__":
main()
5. 查询群成员
import json
import lark_oapi as lark
from lark_oapi.api.im.v1 import *
def main():
# 创建client
client = lark.Client.builder() \
.app_id("YOUR_APP_ID") \
.app_secret("YOUR_APP_SECRET") \
.log_level(lark.LogLevel.DEBUG) \
.build()
# 构造请求对象
request: GetChatMembersRequest = GetChatMembersRequest.builder() \
.chat_id("oc_dcc94d101e8d41e291e90f4623eca17a") \
.member_id_type("user_id") \
.build()
# 发起请求
response: GetChatMembersResponse = client.im.v1.chat_members.get(request)
# 处理失败返回
if not response.success():
lark.logger.error(
f"client.im.v1.chat_members.get failed, code: {response.code}, msg: {response.msg}, log_id: {response.get_log_id()}, resp:
{json.dumps(json.loads(response.raw.content), indent=4, ensure_ascii=False)}")
return
# 处理业务结果
lark.logger.info(lark.JSON.marshal(response.data, indent=4))
if __name__ == "__main__":
main()
文档
Files
5 totalSelect a file
Select a file to preview.
Comments
Loading comments…
