Back to skill

Security audit

Feishu All In One Pro

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a broad workplace-suite integration, but it needs review because it can affect sensitive documents, messages, calendars, approvals, attendance, and recordings without clear user-facing safety boundaries.

Install only if you trust the publisher and can limit the connected workspace permissions. Before use, confirm which actions are read-only versus write/send/record, require explicit approval before modifying documents, sending messages, creating calendar items, uploading/downloading files, changing approvals or attendance records, or recording/transcribing meetings, and avoid granting broad enterprise scopes unless necessary.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises broad read/write/send/recording capabilities across documents, messages, calendars, tables, cloud storage, approvals, attendance, tasks, and meeting transcription, but it does not clearly warn users that it can create, modify, send, upload, download, or record data on their behalf. In an agent setting, this lack of explicit disclosure increases the risk of unintended destructive or privacy-impacting actions because users may invoke the skill without understanding its write side effects.

Static analysis

No suspicious patterns detected.