Back to skill

Security audit

OpenClaw FEISHU MCP

Security checks across malware telemetry and agentic risk

Overview

This Feishu integration is plausible, but it asks users to persist a live-looking app secret and enables automatic cloud document edits without clear controls.

Review before installing. Do not use the embedded app secret; create your own scoped Feishu app credentials, store them securely, verify the MCP endpoint and referenced plugin source, and require explicit confirmation before allowing the agent to write, replace, append, or create Feishu documents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
99% confidence
Finding
The skill documentation includes what appears to be a live Feishu app secret and instructs users to place it directly in a local config file. This creates immediate credential exposure risk through source control, logs, screenshots, local compromise, and reuse by unauthorized parties, potentially allowing access to Feishu APIs and connected document data.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises write, create, table-write, and append operations against cloud documents without any warning that these actions can modify user data. In an agent context, omission of mutation-risk warnings increases the chance of unintended destructive or unauthorized changes to documents, especially if users assume the integration is read-only or low-risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The configuration sends credentials and document operations to a remote MCP endpoint, but the skill provides no privacy or data-transmission warning. Users may unknowingly expose document contents, metadata, and authentication material to an external service, which is especially risky for sensitive enterprise documents.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.