Back to skill

Security audit

Super Lobster

Security checks across malware telemetry and agentic risk

Overview

This Feishu productivity skill has a plausible purpose, but it embeds a real app secret, fixed recipient IDs, and automatic document sharing that users should review before installing.

Install only after removing and rotating the embedded Feishu secret, replacing fixed IDs with your own reviewed configuration, and requiring explicit confirmation before reading meeting notes, creating documents, sending notifications, or granting edit access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly describes automatically reading meeting notes, extracting todos, and pushing outputs, but does not disclose data sensitivity, consent expectations, retention, or who receives the pushed content. Because meeting notes often contain internal business plans, personnel assignments, and deadlines, silent automation here can expose confidential information or process private data beyond user expectations.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documented workflow automatically grants edit permission to a user and enables notifications, but does not warn that it changes document access control. In a collaboration platform, silent permission changes can unintentionally expose or modify sensitive documents, and edit access materially increases the risk of tampering or broader sharing.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The metadata description presents the skill as a broad personal assistant that can read meeting notes, classify work items, create Feishu documents, set permissions, send messages, and run scheduled tasks, but it does not define clear activation boundaries, data sources, or prohibited actions. In combination with granted write/manage/send permissions, this ambiguity increases the risk of overbroad invocation and unintended sensitive-data handling or unauthorized actions in Feishu.

Missing User Warnings

High
Confidence
99% confidence
Finding
The script hardcodes a Feishu/Lark app ID, app secret, and a user open ID directly in source code. Embedded credentials are easily exposed via source control, package distribution, logs, or accidental sharing, allowing unauthorized API access and misuse of the associated tenant or documents.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill sends detailed meeting notes, assignments, names, schedules, and business/project information to Feishu APIs, which is sensitive organizational data. In this skill context, exfiltration risk is elevated because the content includes internal planning, personnel assignments, deadlines, and potentially commercially sensitive project details, yet there is no consent flow, minimization, or data-handling notice.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.