📄 Feishu Doc Manager | 飞书文档管理器

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Feishu document-management skill, but it asks users to install unreviewed external code and can modify documents and permissions without clear safeguards.

Review the GitHub repository before installing, pin a trusted commit if possible, and use a Feishu app or token with only the minimum scopes needed. Treat overwrite, delete, collaborator removal, and permission updates as sensitive actions that should require explicit user confirmation and verified document IDs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill advertises destructive capabilities such as updating permissions, deleting blocks, and removing collaborators, but the user-facing documentation does not clearly warn that these actions can permanently alter document contents or revoke access. In an agent setting, missing safety caveats increases the chance of accidental misuse, especially when the skill combines content publishing with permission management in the same interface.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal