Back to skill

Security audit

OpenClaw Feishu Bot Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Feishu bot configuration purpose, but needs review because dry-run still writes a backup copy and the tool can change or restart OpenClaw automatically.

Install only if you are comfortable letting this skill edit ~/.openclaw/openclaw.json, store Feishu App Secrets there, create local backups, and restart the OpenClaw Gateway. Be aware that --dry-run still creates a backup in the current code; check backup permissions, consider --no-restart, and inspect the generated routing bindings before using it on a production setup.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:275