schedule-feishu

Security checks across malware telemetry and agentic risk

Overview

The skill appears to do what it says, but users should understand that it may automatically remove older schedule entries from a Feishu document.

Before installing, confirm the retention period and whether cleanup can be disabled or backed up. Use a Feishu document where automatic removal of old schedule entries is acceptable, and keep Feishu permissions limited to the schedule data this skill needs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly documents automatic cleanup of historical schedule data but does not present it as a clear upfront user warning or consent-sensitive behavior. Because this skill manages personal schedules in a Feishu document, silent deletion can cause irreversible loss of user data and surprise the user, especially when retention defaults and scheduled cleanup are automatic.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal