Back to skill

Security audit

Feishu Doc Write Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill is a Feishu document-writing helper, but it can update or delete cloud document blocks and handle credentials without enough scoping, confirmation, or privacy guidance.

Review this skill before installing if your Feishu workspace contains important personal or business documents. Use least-privilege Feishu app credentials, avoid providing secrets directly in chat, and require the agent to show the target document, exact changes, and a confirmation step before any update or delete operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill solicits credentials and supports callback/network behavior without any warning that user content and secrets may be transmitted to external services. In an agent context, this can cause users to provide sensitive tokens or approve remote delivery of data without understanding the privacy and security implications.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill describes write, update, and delete operations against remote Feishu documents without warning that these actions modify user-controlled cloud data. In an agent setting, omission of a clear destructive-action warning raises the risk of accidental or unauthorized document changes.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger phrases are broad enough to match ordinary requests like appending content or updating blocks, making accidental invocation more likely. Because this skill performs remote write operations, ambiguous activation increases the chance of unintended changes to Feishu documents.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.