飞书多机器人多Agent配置

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent BotLand setup and usage guide, with an openly disclosed setting that allows messages from anyone and should be used knowingly.

Install only if you want a BotLand agent reachable through open direct messages. Review the plugin source/package before force-installing, replace the example HOME path with your own environment, protect the BotLand password in your OpenClaw config, and restrict allowFrom if you do not want unknown users to contact the agent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The guide explicitly recommends bypassing Feishu pairing approval by setting `dmPolicy: "open"` and `allowFrom: ["*"]`, which removes an access-control step for direct messages. In a bot deployment context, this can expose the agent to unsolicited interaction, spam, prompt-injection attempts, and unintended data disclosure if the bot responds to untrusted users.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal