Feishu Robot Creater For 26462 Final

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only guide for creating a Feishu bot and connecting it to OpenClaw, with expected credential and persistence steps that need careful handling.

Install only if you intend to set up this Feishu/OpenClaw integration. Keep the Feishu App Secret in a protected secret store or secured local configuration, do not paste it into chat or commit it to files, review OpenClaw configuration changes before applying them, and remember that created agent folders, memory, and bot routing persist until removed or disabled.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the user to retrieve and use an App Secret, but does not give strong handling guidance such as never pasting it into chat, storing it only in protected configuration, or rotating it if exposed. In an agent setting, this omission can lead users to disclose a live credential in conversation history or unsafe files, enabling unauthorized access to the Feishu integration.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal