This Feishu automation skill mostly matches its purpose, but it includes an under-disclosed scheduler feature that can run arbitrary local Python scripts from YAML configuration.
Install only if you need high-trust Feishu automation. Use a dedicated least-privilege Feishu app, avoid broad workspace scopes, test with dry-run or local output before bulk updates or publishing, keep snapshots and generated reports out of shared folders and source control, and do not run schedule files from untrusted sources. Review or remove any schedule job with type custom, script, or args because it can execute local Python code with your user permissions.