feishu-cli-meetings
查询飞书历史视频会议、纪要、AI 摘要、逐字稿和录制,按 minute token 读取或下载妙记,操作会议机器人入会/离会及查询会议事件。创建日程、找共同空闲时间和预订会议室使用 feishu-cli-work。
How do I install this agent skill?
npx skills add https://github.com/riba2534/feishu-cli --skill feishu-cli-meetingsIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill provides an interface to Feishu Meetings and Minutes via a CLI tool. It handles sensitive meeting data and supports downloading media. Security controls like SSRF protection and identity boundaries are described. The primary risks are the inherent surface for indirect prompt injection from meeting content and the execution of external CLI commands.
- Socketwarn
1 alert: gptSecurity
- Snykwarn
Risk: MEDIUM · 1 issue
What does this agent skill do?
飞书会议与妙记
读取 references/workflows/vc/workflow.md 后执行。
将该工作流中的 references/、scripts/、templates/、examples/ 相对路径按 workflow.md
所在目录解析;执行脚本时使用解析后的实际路径,不要依赖当前 shell 目录。
身份边界
vc search/notes/recording/detail、vc note detail/transcript和 minutes 命令必须使用 User Token。vc bot meeting-join/meeting-leave默认 Bot 身份,而且只在显式 flag 时切换 User Token。vc bot meeting-events支持--as bot|user|auto(默认 auto),建议按来源显式选身份,须与meeting_id来源一致:--as user预检vc:meeting.meetingevent:read;--as bot确认应用已开通vc:meeting.bot.join:write且机器人须在会中,不能用 Userauth check替代。--as auto刷新/token 文件错误 fail-closed,禁止静默切 Bot;--dry-run只静态探测身份,不联网不写 token。
下载媒体时保留服务端文件名;无法解析扩展名时再按 Content-Type 推导。
搜索会议并下载妙记逐字稿时至少预检:
feishu-cli auth check --scope "vc:meeting.search:read vc:note:read minutes:minutes:readonly minutes:minutes.transcript:export"
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/riba2534/feishu-cli/feishu-cli-meetings">View feishu-cli-meetings on skillZs</a>