Back to skill

Security audit

OpenClaw飞书日历管理

Security checks across malware telemetry and agentic risk

Overview

This calendar skill is instruction-only and purpose-aligned, but it should be reviewed because it encourages persistent calendar changes and broad attendee edit permissions without clear confirmation safeguards.

Install only if you want an agent to manage Feishu calendar data. Before using write actions, confirm the meeting time, timezone, attendees, RSVP change, room booking, and whether invitees should really be allowed to edit the event or manage participants.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The skill hard-codes Asia/Shanghai as the execution timezone and presents it as a fixed rule rather than a default or user-selectable setting. In a calendar-management skill, this can cause meetings to be created, modified, or queried at the wrong times for users in other regions, leading to missed meetings or unintended schedule changes.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The documentation encourages create, patch, reply, attendee add/remove, and other state-changing calendar operations but does not warn about their real-world impact or recommend confirmation before destructive or user-visible changes. In a scheduling skill, this increases the risk of accidental event creation, modification, or participant changes, which can disrupt workflows and send unintended notifications.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.