Caveat verdict
add-feishu
The skill adds Feishu as a channel and does not show any malicious behavior.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
agent_memory
Findings (4)
Instruction-prose smuggling shape detected: collects a sensitive target ("Credentials") and emits it outward ("Send"). Phrased as prose with no trigger tokens โ a semantic prompt-injection / data-exfil pattern the syntactic scanners can't see. Final tier capped at Caution; review the instructions before installing.
SKILL.md ยท > I need you to create a Feishu app: > > 1. Go to [Feishu Open Platform](https://open.feishu.cn) (or [Lark Open Platform](https://open.larksuite.com) for intern
Opens WebSocket connection
SKILL.md ยท frontmatter ยท WebSocket
References tunneling service
SKILL.md ยท frontmatter ยท ngrok
Accesses sensitive environment variables
add/src/channels/feishu.ts ยท prose ยท downgraded ยท process.env.FEISHU_APP_SECRET
Permissions & capabilities
No declared permissions โ minimal attack surface.
agent_memory Is this flag fair?
Thanks โ recorded.