Back to skill

Security audit

协作平台卡片

Security checks across malware telemetry and agentic risk

Overview

This skill is a user-directed Feishu card sending helper with expected network and credential use, but users should be careful with message contents and any callback URL.

Install only if you intend to let the agent send Feishu collaboration messages using your configured credentials. Review message text, recipients, image paths, button links, and any callback_url before use, and avoid sending secrets or sensitive logs unless the destination is trusted.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Low
Confidence
90% confidence
Finding
The undocumented callback_url behavior creates ambiguity around when and where data may be sent after processing. In an agent environment with read/exec/write tools and external messaging, this can lead to unintended outbound requests or quiet exfiltration of processed content to attacker-controlled endpoints.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly supports an external callback URL but does not warn users that message content, metadata, or execution results may be transmitted off-platform. In this context, the skill is a communication/integration tool, so silent external delivery materially increases data exfiltration risk, especially if sensitive logs, reports, or alerts are included.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.