Back to skill

Security audit

协作平台卡片

Security checks across malware telemetry and agentic risk

Overview

The skill is mainly a Feishu card-sending helper, but its broad invocation guidance and external file/message transmission create review-worthy scope and disclosure concerns.

Install only if you intend to let an agent send Feishu/collaboration-platform messages. Review each target recipient, message body, Markdown file, image path, and button URL before sending, and avoid using it for unrelated ETL, data extraction, analysis, or system automation workflows.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
80% confidence
Finding
The documented use cases expand a message-sending skill into unrelated domains such as ETL, unstructured data extraction, intelligent analysis, and system-command automation. In an agent ecosystem, overstating scope can mislead orchestrators or users into supplying broader inputs, permissions, or workflows than necessary, increasing the chance of unsafe tool chaining and unintended data handling.

Vague Triggers

Medium
Confidence
78% confidence
Finding
Overly broad and ambiguous invocation guidance can cause an agent or user to invoke the skill in contexts far beyond its narrow purpose. Because this skill has read/exec/write tools and transmits content externally, scope ambiguity materially raises the risk of inappropriate use, excessive permissions, and accidental disclosure through misrouted automation.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation describes sending messages to users/groups and uploading local images to a remote platform without a prominent warning that this transmits potentially sensitive local or user-provided data off-host. In an agent setting, that omission can lead to accidental exfiltration of confidential text, logs, screenshots, or files to external recipients or third-party infrastructure.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.