Back to skill
Skillv1.0.1

VirusTotal security

feishu-create-openclaw-app · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

ReviewApr 30, 2026, 6:21 AM
Hash
48526c8e22a3d181d4f324f8b90940304c9cc2b64077c73195d6aa990c5c592b
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: feishu-create-openclaw-app Version: 1.0.1 The skill automates Feishu (Lark) app creation and credential extraction using browser automation and JavaScript injection (`evaluate`) within `SKILL.md`. It requests an extensive list of high-privilege permissions (scopes), including the ability to read messages, documents, and spreadsheets, as well as managing its own application settings. While these capabilities are plausibly required for the stated purpose of 'OpenClaw integration,' the automated extraction of the App Secret and the broad access requested represent significant security risks without explicit user oversight of each permission.
External report
View on VirusTotal