Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 70% confidence
- Finding
- Without declared permissions the skill's intent is opaque and cannot be validated.
Security checks across malware telemetry and agentic risk
This skill openly patches local OpenClaw Feishu files so group chat replies go into threads, with no evidence of hidden data access or exfiltration.
Before installing, confirm you want local OpenClaw Feishu behavior changed for all group replies. Run the check-only commands first, consider backing up the affected files on production systems, and only add the heartbeat auto-reapply steps if you want the patch restored after plugin updates.
64/64 vendors flagged this skill as clean.