Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Feishu Sheets (Fixed)

v1.0.1

Feishu online spreadsheet (Sheets) operations including create, read, write, append data, manage worksheets. Use when user mentions Feishu Sheets, online spr...

0· 144·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
The skill claims to provide Feishu Sheets operations and the included Python client implements those APIs — that part is coherent. However the registry metadata declares no required environment variables or primary credential, while the code clearly requires FEISHU_APP_ID and FEISHU_APP_SECRET (to obtain a tenant_access_token). Additionally, package metadata (_meta.json) and registry metadata (ownerId/slug/version) are inconsistent, which raises supply-chain/trust concerns.
!
Instruction Scope
SKILL.md documents the actions and API endpoints but does not instruct how to provide the required app credentials or tenant token; it also provides slightly different guidance for append/write endpoints compared to the bundled references and code. The run-time instructions therefore omit authentication setup that the code will perform by reading environment variables, creating an operational gap and potential confusion.
Install Mechanism
This is an instruction-only skill with an included Python script; there is no install spec (no dependencies or packaging). That lowers installer risk (nothing is downloaded at install time), but the script depends on the 'requests' library and expects to be executable as a CLI. The lack of install/dependency declaration may cause runtime failure and makes reproducibility unclear rather than introducing direct malicious risk.
!
Credentials
The code requires FEISHU_APP_ID and FEISHU_APP_SECRET (to call the Feishu internal auth API and obtain a tenant_access_token). Those credentials are appropriate for the stated purpose, but the skill metadata does not declare them (no required env vars, no primary credential). This mismatch is significant: a user installing the skill might not realize they must provide sensitive app credentials, and the skill will read them from environment variables without explicit disclosure in the registry metadata.
Persistence & Privilege
The skill is not always-included and does not request any elevated platform privileges. It does not modify other skills' configs and does not request persistent presence beyond normal operation.
What to consider before installing
This package implements a Feishu Sheets client and will call Feishu's APIs, but it has three red flags you should address before installing: 1) Authentication is required but not declared: the Python script reads FEISHU_APP_ID and FEISHU_APP_SECRET from environment variables to obtain a tenant_access_token. The registry metadata lists no required env vars or primary credential. Only provide those app credentials if you trust the skill owner and have isolated the credentials to an app with minimal privileges. 2) Metadata inconsistencies: _meta.json disagrees with the registry metadata (ownerId/slug/version). Confirm who published this skill and that the package you received matches the registry listing — this could be an accidental mispackaging or indicate a supply-chain issue. 3) Documentation vs code mismatches: the SKILL.md, the API reference, and the Python code differ slightly on endpoints for append/write/add-sheet. Test in a safe environment before using on production spreadsheets. Recommended actions: - Ask the publisher to update registry metadata to declare FEISHU_APP_ID and FEISHU_APP_SECRET (and a primary credential) and to fix version/owner inconsistencies. - Limit the Feishu app credentials to the minimum scopes and use a test tenant/app first. - Review the code locally (it is included) and run it in an isolated environment to verify behavior and to ensure it does not exfiltrate data to unexpected endpoints (it contacts only open.feishu.cn in the provided code). - If you cannot verify the publisher or do not want to expose app credentials, do not install or run this skill.

Like a lobster shell, security has layers — review code before you run it.

latestvk97b6nnqqsjcpqmptwr2e6bw09837mbq

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments