Back to skill

Security audit

飞书文档翻译助手

Security checks across malware telemetry and agentic risk

Overview

This appears to be a Feishu document translation skill whose document read/write behavior is aligned with its purpose, but users should confirm where translated output will be written.

Install if you want Feishu document translation, but review each run's source document and destination before allowing writes. Prefer creating a new translated copy unless you intentionally want the source or an existing document changed, and avoid using it on confidential documents unless your Feishu permissions and retention expectations are clear.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly reads Feishu documents and creates or writes translated output, but it does not warn users that it may create new documents or modify existing content. This can lead to unintended document changes, duplicate sensitive content in translated copies, and accidental propagation of confidential information into additional files or locations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal