Security audit
Model Pricing Sync
Security checks for vulnerabilities and agentic risk
Overview
The skill matches its pricing-sync purpose, but it can use a local Lark/Feishu identity to create, overwrite, and delete spreadsheet tabs without clearly declaring that account-level access.
Install only if you are comfortable giving the skill access to a configured Lark/Feishu CLI account. Before running push, verify the spreadsheet destination, back up any important tabs, and expect the managed sheets to be deleted and recreated. Review the dependency installation steps and keep sheet_state.json protected.
Static analysis
No suspicious patterns detected.
