Back to skill

Security audit

Feishu Send Message

Security checks across malware telemetry and agentic risk

Overview

This Feishu reporting skill has a coherent purpose, but it can use local bot credentials to send messages as a caller-selected agent without clear approval or target limits.

Install only if you want agents to send Feishu messages automatically and you trust them with the relevant Feishu bot credentials. Before use, restrict file permissions on ~/.openclaw configs, use least-privilege Feishu apps, pre-approve allowed open_id/chat_id destinations, and avoid sending secrets or sensitive task output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs agents to automatically scan local configuration files for Feishu app credentials and use them to send messages, but it does not document consent, scope limits, or the privacy/security implications of accessing those secrets. In an agent environment, automatic secret discovery materially increases the risk of unauthorized credential use, cross-agent secret access, and covert outbound messaging, especially because the skill is designed for zero-configuration autonomous use.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.