Back to skill

Security audit

feishu-team-manager

Security checks across malware telemetry and agentic risk

Overview

This skill matches its stated Feishu/Discord team-management purpose, but it warrants Review because it encourages bypassing install warnings and can make persistent, broad changes to your OpenClaw agent routing.

Install only if you are comfortable with this skill modifying ~/.openclaw/openclaw.json, creating persistent agent workspaces, copying itself into an HR workspace, and configuring bot routing. Do not use --force just because the docs say warnings are normal; first review the source, back up OpenClaw config, keep bot tokens in environment variables, and restrict Discord/Feishu sender access instead of using open or wildcard defaults.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:44