Feishu Calendar Meeting.Tmp
PassAudited by VirusTotal on Mar 27, 2026.
Findings (1)
The skill facilitates Feishu calendar and meeting management but is classified as suspicious due to its use of risky capabilities, including local file system access to store and read sensitive OAuth tokens (~/.openclaw/workspace/feishu_tokens.md) and outbound network requests to the Feishu API (open.feishu.cn). Additionally, the bash templates provided in SKILL.md are vulnerable to shell injection, as they demonstrate direct interpolation of user-controlled variables into shell commands without any input sanitization or escaping.
