Back to skill

Security audit

Feishu Channel Cleaner

Security checks across malware telemetry and agentic risk

Overview

This skill is a focused Feishu configuration repair tool that edits one OpenClaw config file after making a backup, with no evidence of hidden network access or unrelated behavior.

Install only if you intend to repair Feishu channel conflicts in OpenClaw. Before running it, know that it can rewrite `~/.openclaw/openclaw.json`, remove one duplicate Feishu channel entry, and clean unrecognized fields; keep the `.bak` backup available in case the gateway behavior changes afterward.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger text includes 'or similar keywords,' which makes activation scope ambiguous and can cause the skill to run in situations the user did not clearly intend. In a skill with config:write and gateway:restart permissions, overly broad activation increases the risk of unintended configuration modification from loosely related requests.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The markdown describes automatic backup, merge, cleanup, and deletion of configuration data without a prominent warning that the skill will modify live configuration. In this context, the skill has config:write and gateway:restart permissions, so insufficient disclosure can lead users to authorize irreversible or service-impacting changes without informed consent.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The script writes modified configuration back to the live OpenClaw config and deletes one channel entry automatically, with no confirmation, dry-run mode, or rollback beyond a backup file. Because this skill has config:write and gateway-related operational context, an accidental trigger or incorrect merge decision can disrupt bot behavior, remove settings, or cause unintended service changes.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.