feishu-share-link

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Feishu link-formatting skill that reads one disclosed local configuration file to find a custom Feishu domain.

Before installing, make sure ~/.openclaw/workspace/TOOLS.md contains only intended configuration such as the Feishu custom domain. If you do not want the agent reading that file, provide the Feishu domain manually when asking it to generate share links.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
90% confidence
Finding
The README explicitly instructs the skill to read a local file from the user's home directory to obtain configuration, but it does not clearly disclose that this is local data access or define any scope limits. Even if the target file is meant for benign configuration, silently reading local files expands the skill's trust boundary and can lead to unintended exposure of locally stored information.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal