Back to skill

Security audit

飞书文档写入(免费版)

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a Feishu document automation guide, but it expands from append-focused writing into create, export, modify, and delete operations without clear safeguards.

Review this as a broad Feishu document management skill, not just an append tool. Only install it if you are comfortable giving an agent Feishu document credentials and authority to create, update, export, and delete document blocks; use least-privilege Feishu app permissions and require explicit confirmation for destructive operations.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill is presented as a document writing/append tool, but the documented capabilities expand to creation, query, export, and potentially broader state-changing actions. This mismatch can mislead users and downstream agents into granting or invoking more powerful operations than expected, increasing the chance of unintended data access or modification.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The documentation explicitly claims support for create/query/modify/delete modes despite branding the skill as a Feishu document write tool. Hidden or under-disclosed destructive capabilities are dangerous because users may authorize the skill for benign writing tasks while it also supports deletion or broad modification of remote document content.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation examples are generic natural-language phrases such as appending content or updating document blocks, which can easily overlap with ordinary user conversation. In an agent environment, broad trigger phrases increase the risk of accidental invocation and unintended remote actions against Feishu documents.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill describes modification and deletion capabilities but does not provide a clear user-facing warning that it can alter or remove remote document content. In this context, lack of disclosure is especially risky because the tool targets external collaborative documents where unintended changes can cause data loss or business disruption.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.