Back to skill

Security audit

Feishu Card Builder Free

Security checks across malware telemetry and agentic risk

Overview

This skill is mainly a Feishu/Lark card sender, but it also advertises unrelated writing and marketing triggers that could cause content to be sent externally in the wrong context.

Install only if you want the agent to send Feishu/Lark card messages. Before use, make sure the agent confirms the recipient, message body, files/images, and send action, and avoid letting this skill handle ordinary writing or marketing-drafting requests unless you intend the result to be sent externally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The manifest frames the skill as a card-building utility, but the body clearly instructs the agent to send messages, upload images, and interact with Feishu APIs. This mismatch can mislead users and downstream policy systems about the skill's real network and outbound-communication behavior, increasing the chance of unintended data transmission.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The capability coverage text includes unrelated marketing-copy and content-creation scenarios that do not match the documented Feishu card-sending purpose. Overbroad or misleading scope claims can cause the skill to activate in inappropriate contexts and route unrelated user content into a messaging workflow, risking accidental exfiltration or misuse.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill advertises broad activation phrases like marketing copy, title optimization, and content creation even though its operational effect is to send content externally via Feishu. That mismatch is dangerous because an agent may invoke this skill for unrelated drafting tasks and inadvertently transmit sensitive or unfinished user content to external recipients.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation does not clearly warn that using the tool sends message bodies, links, and images to external Feishu users or groups over the network. Without an explicit disclosure, users may provide sensitive content under the assumption that the skill only formats cards locally, leading to unintended data exposure.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.