Back to skill

Security audit

Feishu Bridge

Security checks across malware telemetry and agentic risk

Overview

This is a transparent Feishu-to-Clawdbot bridge with expected sensitive setup steps, though users should update its WebSocket dependency and understand that chat messages will be routed through the bridge.

Install only if you want the configured Feishu bot to pass chat text to your local Clawdbot agent and post replies back. Protect the Feishu secret and Clawdbot token, restrict the bot to intended chats, review the group-response rules, update and lock the ws dependency to a fixed version, and unload the LaunchAgent when you do not want the bridge running.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Known Vulnerable Dependency: ws==8.18.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
95% confidence
Finding
ws==8.18.0

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.