Back to skill

Security audit

飞书日历基础版

Security checks across malware telemetry and agentic risk

Overview

This calendar skill has legitimate Feishu/Lark calendar functions, but its routing, privacy claims, and collaboration scope are materially inconsistent for a tool with calendar write access.

Review before installing. Use this only for Feishu/Lark calendar tasks, and treat it as capable of reading calendars, reading contacts, creating events, adding attendees, and storing synced calendar data locally. Do not rely on the stated local-only privacy claim unless the publisher clarifies what is sent to Feishu/Lark and what is cached locally.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest description conflates a Feishu/Lark calendar tool with unrelated SEO optimization use cases, which can cause the agent to invoke this skill for requests far outside its intended calendar scope. Because the skill has exec capability and can create/modify calendar data, mismatched routing increases the chance of unintended side effects, data access, or execution in the wrong context.

Intent-Code Divergence

Medium
Confidence
87% confidence
Finding
The documentation says the FREE edition does not support team collaboration, yet later examples and capabilities include attendee management and shared-calendar setup. This inconsistency can mislead users and agents about what actions may occur, resulting in unexpected modifications to other users' calendars or collaborative resources.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The skill claims FREE-version data is stored locally and not uploaded to the cloud, but the rest of the document explicitly requires external API access to Feishu/Lark. This creates a false privacy and data-handling assurance that could cause users to expose calendar contents, attendee identities, and credentials under incorrect assumptions about where data is transmitted.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger conditions instruct use for data analysis, reporting, statistical insight, and visualization, which are unrelated to a calendar-management skill. Overbroad or incorrect routing guidance can cause the agent to select this skill for unrelated prompts, increasing the risk of unnecessary exec usage or accidental calendar reads/writes when the user did not intend calendar operations.

Vague Triggers

High
Confidence
98% confidence
Finding
The description includes broad, conflicting invocation guidance that overlaps with unrelated SEO and general work-assistance requests. In an agentic environment, ambiguous skill descriptions can hijack routing decisions, causing this exec-enabled skill to be selected in contexts where it should never run and leading to unintended actions on calendars or local state.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The capability list describes creating calendar events, setting attendees, and syncing to local state without a prominent warning that the skill can modify external calendar data and persist synchronized data locally. Users and agents may therefore treat it as read-only or low-risk, leading to accidental writes, participant notifications, or local storage of sensitive scheduling information.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.