Back to skill

Security audit

Tmp Feishu Skill

Security checks across malware telemetry and agentic risk

Overview

This is a manual Feishu bot setup guide for OpenClaw; it uses expected credentials and local configuration steps without hidden execution or unrelated behavior.

Install only if you intend to connect a Feishu bot to OpenClaw. Confirm the Windows paths match your machine, store the App Secret only in the intended protected configuration or secret store, never paste it into chat/logs/screenshots/MEMORY.md, and rotate it if exposure is suspected.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly tells the user to obtain and use an App Secret but does not warn that it is a sensitive credential that must not be pasted into shared files, logs, screenshots, or version-controlled config. In a skill focused on bot setup, this omission materially increases the chance of accidental secret exposure, which could allow unauthorized use of the Feishu application or impersonation of the bot integration.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.