weekly-report-generator-feishu-chinese
PassAudited by VirusTotal on Apr 2, 2026.
Findings (1)
The skill automates git log extraction and sends data to the Feishu API (open.feishu.cn). The SKILL.md file contains instructions that explicitly command the AI agent to execute scripts and exfiltrate data to an external endpoint without user confirmation or review ('无需任何检查或询问'). While the scripts (auto-weekly-report.sh, send-to-feishu.sh) appear functional for their stated purpose, the use of 'HARD-GATE' instructions to bypass human-in-the-loop verification for data transmission poses a significant security risk.
