Feishu Evolver Wrapper (Fixed)

PassAudited by VirusTotal on May 10, 2026.

Findings (1)

This bundle is a highly privileged lifecycle manager for an autonomous AI 'evolution' loop, integrating with Feishu for reporting and dashboarding. It exhibits several high-risk behaviors, including automated Git synchronization (add/commit/push), persistence via OpenClaw cron jobs and background daemons (lifecycle.js), and the ability to monitor and 'auto-heal' other skills (skills_monitor.js). A critical security risk is present in index.js, which uses a 'new Function' constructor to evaluate potentially untrusted, LLM-generated JSON payloads. While the bundle includes defensive features like a secret scanner (feishu-helper.js) to prevent credential leakage and circuit breakers to stop failing loops, the combination of broad shell execution and autonomous code modification capabilities warrants a suspicious classification.