Back to skill

Security audit

OpenClaw Feishu Message

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it ships exposed contact data and can send real Feishu/Lark messages with weak recipient safeguards.

Review before installing. Remove the bundled contact-cache data, require preview and explicit confirmation for sends, reject ambiguous recipient matches, and scope or disable plaintext caching before using this with real Feishu/Lark accounts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
data/contact-cache.json:174
Finding

Production-Like Contact PII Included in the Distributed Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/cache.js:4
Finding

Contact Records Persisted in Plaintext Without Explicit Restrictive Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/cache.js:30
Finding

Global Contact Cache Is Not Scoped by Feishu Account or Tenant

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/tool-feishu-message.js:491
Finding

Message Actions Silently Select the First Ambiguous Directory Match

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code persistently stores personally identifiable contact data such as name, email, mobile number, and platform identifiers in a plaintext JSON file under a fixed path. In the context of a messaging skill that resolves and contacts real users, this creates unnecessary long-lived exposure of sensitive data to local attackers, other processes, backups, or logs if the host is shared or compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The send_message action can transmit a live Feishu/Lark message immediately once called, gated only by pluginCfg.allowSend and without any in-code confirmation, approval, or enforced dry-run step. In an agent skill, this creates a real risky side effect: prompt injection, user ambiguity, or mistaken target resolution could cause unintended outbound messages to employees or chats.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The send_followup path builds a message and, unless dry_run is set, proceeds to send it live without requiring an explicit user-facing confirmation in code. Because this tool is specifically designed for work follow-ups and can resolve recipients from partial identifiers, an agent mistake or adversarial prompt could generate and send unintended nudges to the wrong person.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The send_contact_message action can send arbitrary content to a resolved contact or chat immediately when dry_run is not set, again without mandatory confirmation in the code path. This is dangerous in an agent context because the action supports free-form message content and target lookup, enabling accidental spam, disclosure, or social-engineering messages if the model is manipulated or misinterprets instructions.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency uses a caret range, which permits automatic installation of newer minor/patch releases rather than a single immutable version. This weakens supply-chain reproducibility and can unexpectedly introduce vulnerable or malicious upstream code if the resolved package changes over time.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"description": "Feishu/Lark messaging plugin for OpenClaw with contact lookup, caching, direct messaging, and follow-up actions.",
  "keywords": ["openclaw", "feishu", "lark", "message", "im", "chat"],
  "dependencies": {
    "@larksuiteoapi/node-sdk": "^1.59.0",
    "@sinclair/typebox": "^0.34.48",
    "openclaw": "^2026.3.22",
    "zod": "^4.3.6"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a non-exact version range, so different installs may resolve to different package contents. This creates a supply-chain risk and reduces build determinism, making it harder to verify exactly what code is executed.

Content

Scanner excerpt · package.json (reported line 9)May include surrounding context.

json
"keywords": ["openclaw", "feishu", "lark", "message", "im", "chat"],
  "dependencies": {
    "@larksuiteoapi/node-sdk": "^1.59.0",
    "@sinclair/typebox": "^0.34.48",
    "openclaw": "^2026.3.22",
    "zod": "^4.3.6"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The openclaw dependency is not pinned to an exact version, allowing installs to drift across releases. In this case the risk is elevated because the package is the host framework for the skill and is reported to have multiple advisories, so version ambiguity makes it impossible to determine exposure and can pull in vulnerable code.

Content

Scanner excerpt · package.json (reported line 10)May include surrounding context.

json
"dependencies": {
    "@larksuiteoapi/node-sdk": "^1.59.0",
    "@sinclair/typebox": "^0.34.48",
    "openclaw": "^2026.3.22",
    "zod": "^4.3.6"
  },
  "openclaw": {

Unverifiable Dependency: openclaw has 16 known advisory(ies) (CVE-2026-53846 (OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency); CVE-2026-32064 (OpenClaw's andbox browser noVNC observer lacked VNC authentication); CVE-2026-32006 (OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallbac) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The manifest does not pin openclaw to an exact version, and the package has multiple known advisories. Because the actual installed version cannot be verified from this manifest alone, consumers may unknowingly deploy a vulnerable release, which is more concerning here because the skill runs inside and depends on the OpenClaw runtime.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

Using a caret range for zod allows the installed version to change without explicit review. Even if only patch/minor updates are expected, this still introduces uncertainty and can expose the skill to newly disclosed or compromised upstream releases.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
"@larksuiteoapi/node-sdk": "^1.59.0",
    "@sinclair/typebox": "^0.34.48",
    "openclaw": "^2026.3.22",
    "zod": "^4.3.6"
  },
  "openclaw": {
    "extensions": ["./index.js"]

Unverifiable Dependency: zod has 1 known advisory(ies) (CVE-2023-4316 (Zod denial of service vulnerability)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The zod version is not pinned exactly, and the package has a known advisory history. This makes it unclear whether deployments will resolve to a safe release, creating avoidable exposure and hindering reliable vulnerability assessment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code accesses configuration from process.env.OPENCLAW_CONFIG_PATH and ~/.openclaw/openclaw.json, which involves reading user/system data from potentially sensitive locations. There is no confirmation prompt, user-facing log, or explanatory comment/docstring disclosing that these files and environment-derived paths will be accessed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.