Book a 30-minute demo →
Skill scan report

feishu-cli-visual

View on GitHub
45 Medium Automated analysis flagged 3 potential risk patterns.

What this skill does

The skill is a CLI tool for interacting with Feishu (Larksuite) services, specifically for creating and managing visual diagrams, boards, and applications. It includes workflows for SVG to board conve

github/riba2534 - MCP Least Privilege - 1.3k stars

ThreatsMCP Least Privilege Data Flow

Threat analysis

MCP Least Privilege1 finding
Data Flow2 findings

Skill info

Nameriba2534/feishu-cli-visual
Registrygithub
Versionfbe60e0
PURLpkg:github/riba2534/feishu-cli@fbe60e0?skill=feishu-cli-visual
Stars1.3k

Assessments (3)

MCP Least Privilege1 finding HIGH
HIGH

MCP Least Privilege via local-llm-review

references/workflows/apps/workflow.md

The skill references `.aws/credentials` which could indicate a potential risk if the tool is accessing AWS credentials without proper least privilege controls.
Data Flow2 findings MEDIUM
MEDIUM

Data Flow via local-llm-review

references/workflows/board/scripts/svg_to_board.py

The use of `subprocess.run` with `capture_output=True` could be a risk if the command being executed is not properly sanitized or if it's handling sensitive data.
MEDIUM

Data Flow via local-llm-review

references/workflows/htmlbox/scripts/animate_diagram.py

The use of `write_text` with `render(pattern)` could be a risk if the `render` function is not properly sanitizing the input or if it's writing to a file that could be accessed by others.

Badge

Add the Anomity scan badge for feishu-cli-visual to your README.

Anomity Skill Check badge

Markdown
[![Anomity Skill Check](https://anomity.ai/skills/badge.svg)](https://anomity.ai/skills/github/riba2534/feishu-cli-visual/)
HTML
<a href="https://anomity.ai/skills/github/riba2534/feishu-cli-visual/"><img src="https://anomity.ai/skills/badge.svg" alt="Anomity Skill Check"></a>
Image URL
https://anomity.ai/skills/badge.svg

How Anomity governs this at runtime

Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.

Book a 30-minute demo to see your own skill inventory.

Methodology and disputes

Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of feishu-cli-visual? Report an issue or request a rescan.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok