Atlas / MCP servers / cso1z / Feishu

FeishuBLOCK

mcp/cso1z/feishu

Feishu / Lark 飞书文档与任务管理工具,支持 MCP 服务器和 CLI + Skill 两种使用方式,可无缝集成 Cursor、Claude Code、Cline 等 AI 编码工具

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
24 14r · 8w · 2d
Transport
sse · stdio · streamable-http
License
MIT
Stars
741
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/feishu-mcp) [](./LICENSE)

为 Cursor、Windsurf、Cline 和其他 AI 驱动的编码工具提供访问、编辑和结构化处理飞书文档的能力,并支持飞书任务管理和用户信息查询,基于 Model Context Protocol 服务器实现。

现已支持 `feishu-tool` 独立 CLI 工具,可在终端或脚本中直接调用所有飞书工具,无需启动 MCP 服务器。配合 Feishu-Skill 可让 Claude Code 等 AI Agent 自动选择最合适的方式操作飞书。

本项目让 AI 编码工具能够:

  • 文档处理:直接获取、理解、创建和编辑飞书文档,显著提升文档处理的智能化和效率
  • 任务管理:列取、创建、更新、删除飞书任务,支持子任务和成员管理(需 user 认证)
  • 用户信息:按名称搜索或按 ID 批量获取飞书用户,便于任务分配和文档协作(需 user 认证)

完整覆盖飞书文档的真实使用流程,助你高效利用文档资源:

  1. 文件夹目录获取:快速获取和浏览飞书文档文件夹下的所有文档,便于整体管理和查找。
  2. 内容获取与理解:支持结构化、分块、富文本等多维度内容读取,AI 能精准理解文档上下文。
  3. 智能创建与编辑:可自动创建新文档、批量生成和编辑内容,满足多样化写作需求。
  4. 高效检索与搜索:内置关键字搜索,帮助你在大量文档中迅速找到目标信息。
  5. 任务管理与用户查询:支持飞书任务 CRUD 及用户信息搜索,便于在文档中关联任务和人员。

本项目让你在飞书文档的日常使用流程中实现智能获取、编辑和搜索,并扩展任务与用户管理能力,提升内容处理效率和体验。

💡项目推荐:

使用 Claude Code 推荐配合 claude-ip-guard —— 自动检测 IP 地理位置并拦截受限地区访问,防止因网络切换导致 Claude 封号。

🎬 使用演示视频

你可以通过以下视频了解 MCP 的实际使用效果和操作流程:

⭐ Star 本项目,第一时间获取最新功能和重要更新! 关注项目可以让你不错过任何新特性、修复和优化,助你持续高效使用。你的支持也将帮助我们更好地完善和发展项目。⭐

🛠️ 工具功能详情

Read from source at commit b654d121ad29OBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add feishu-mcp --env FEISHU_APP_SECRET=${FEISHU_APP_SECRET} --env FEISHU_AUTH_BASE_URL=${FEISHU_AUTH_BASE_URL} --env FEISHU_AUTH_TYPE=${FEISHU_AUTH_TYPE} --env FEISHU_ENCRYPTION_KEY=${FEISHU_ENCRYPTION_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "feishu-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "FEISHU_APP_SECRET": "${FEISHU_APP_SECRET}",
        "FEISHU_AUTH_BASE_URL": "${FEISHU_AUTH_BASE_URL}",
        "FEISHU_AUTH_TYPE": "${FEISHU_AUTH_TYPE}",
        "FEISHU_ENCRYPTION_KEY": "${FEISHU_ENCRYPTION_KEY}"
      }
    }
  }
}
03

Exposed tools (24)

14 read · 8 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
batch_create_feishu_blockswriteCreates one or more blocks at a specified position within a Feishu document. Supports text, code, heading, list, image, mermaid, and whiteboard block types. Accepts any number of blocks.
batch_update_feishu_block_textwriteUpdates text content and styling of multiple document blocks.
create_feishu_documentwrite
create_feishu_folderwriteCreates a new folder in a specified parent folder. Use this to organize documents and files within your Feishu Drive structure. Returns the token and URL of the newly created folder.
create_feishu_tablewriteCreates a table block with specified rows and columns in a Feishu document. Each cell can contain text, list, code, or other block types.
create_feishu_taskwrite
delete_feishu_document_blocksdestructiveDeletes a consecutive range of blocks from a Feishu document identified by startIndex (inclusive) and endIndex (exclusive).
delete_feishu_taskdestructiveDeletes one or more Feishu tasks by task_guid. Pass an array of task GUIDs (min 1, max 50). Requires edit permission on each task. Returns deleted guids and per-item errors. Deleted tasks cannot be retrieved.
fill_whiteboard_with_plantumlreadFills whiteboard blocks with PlantUML or Mermaid diagram code. Accepts any number of whiteboards. Returns per-item success/failure details.
get_feishu_document_blocksreadRetrieves the block hierarchy of a Feishu document, including block IDs, types, and content.
get_feishu_document_inforead
get_feishu_folder_filesread
get_feishu_image_resourcereadDownloads an image resource from Feishu by its media ID and returns binary image data. To get the mediaId, extract block.image.token from an image block (block_type=27) returned by get_feishu_document_blocks.
get_feishu_root_folder_inforeadRetrieves the root folder in Feishu Drive, wiki spaces list, and
get_feishu_usersread
get_feishu_whiteboard_contentreadRetrieves the content and structure of a Feishu whiteboard. Use this to analyze whiteboard content, extract information, or understand the structure of collaborative diagrams. The whiteboard ID can be obtained from the board.token field when getting document blocks with block_type: 43.
list_feishu_tasksreadLists tasks assigned to the current user (
search_feishu_documentsread
update_feishu_taskwriteUpdates an existing Feishu task. Provide task_guid and the fields to change. Supports summary, description, due, completed_at (use
upload_and_bind_image_to_blockwrite
飞书任务read飞书任务查询、创建、更新、删除功能
飞书成员read通过用户名关键词搜索用户,返回头像、部门、open_id 等,用于任务指派(1 个工具)
飞书文档read飞书文档、块操作、文件夹和知识库管理
飞书日历read飞书日历和日程管理
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (17)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/cli/commands/auth.ts:28
exec(cmd, (err) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/modules/document/services/FeishuFoldService.ts:64
Logger.debug(`文件夹创建成功, token: ${response.token}, url: ${response.url}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/server.ts:131
Logger.warn(`[Bearer Auth] Token 验证失败: ${req.method} ${req.url}, 请求token长度=${token.length}, 配置token长度=${bearerToken.length}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/utils/auth/legacyCacheMigration.ts:56
Logger.debug(`Token 缓存迁移完成,共 ${migratedCount} 个文件`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/utils/config.ts:529
Logger.info(`- Bearer Token 认证: ${this.server.bearerToken ? '已启用' : '未启用'} (来源: ${this.configSources['server.bearerToken']})`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/utils/config.ts:536
Logger.info(`- App Secret: ${Logger.maskSecret(this.feishu.appSecret)} (来源: ${this.configSources['feishu.appSecret']})`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/utils/config.ts:251
tokenEndpoint: `http://127.0.0.1:${serverConfig.port}/getToken`, // 默认动态端口
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_feishu_document_blocks, delete_feishu_task
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/auth.ts:5
import { Config } from '../../utils/config.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/auth.ts:6
import { AuthUtils, TokenCacheManager } from '../../utils/auth/index.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/auth.ts:7
import { Logger } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/auth.ts:8
import { getRequiredScopes } from '../../services/constants/feishuScopes.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/auth.ts:9
import { ModuleRegistry } from '../../modules/index.js';
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
doc/feishu-handler.ts:123
const oauthReqInfo = JSON.parse(atob(c.req.query("state") as string)) as AuthRequest;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/yargs, axios, cross-env, dotenv, express, form-data, remeda
Why it matters. 23 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:317
curl -X POST -H "Authorization: Bearer your-secret-token-here" -H "Content-Type: application/json" http://localhost:3333/mcp?userKey=123456
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha b654d121ad29full audit observations/trust-audit/mcp-server/cso1z__feishu.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-28b654d121ad29BLOCKD69first audit
06

Questions

What is the Feishu MCP server?

Feishu / Lark 飞书文档与任务管理工具,支持 MCP 服务器和 CLI + Skill 两种使用方式,可无缝集成 Cursor、Claude Code、Cline 等 AI 编码工具

What tools does Feishu expose?

24 in total: 14 read-only, 8 that write, and 2 that can delete or overwrite (delete_feishu_document_blocks, delete_feishu_task). Every one is listed on this page with its risk.

Is Feishu safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Feishu need?

It reads FEISHU_APP_SECRET, FEISHU_AUTH_BASE_URL, FEISHU_AUTH_TYPE, FEISHU_ENCRYPTION_KEY, FEISHU_REQUIRE_USER_KEY, FEISHU_TOKEN_ENDPOINT, FEISHU_USER_KEY and MCP_BEARER_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Feishu run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as feishu-mcp at 0.3.3.

How current is this page?

The grade is for one exact copy of the source (b654d121ad29), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement