Back to skill

Security audit

Model Pricing Sync

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its pricing-sync purpose, but it can use a local Lark/Feishu identity to create, overwrite, and delete spreadsheet tabs without clearly declaring that account-level access.

Install only if you are comfortable giving the skill access to a configured Lark/Feishu CLI account. Before running push, verify the spreadsheet destination, back up any important tabs, and expect the managed sheets to be deleted and recreated. Review the dependency installation steps and keep sheet_state.json protected.

Static analysis

No suspicious patterns detected.