Security audit
feishu-log
Security checks for vulnerabilities and agentic risk
Overview
The skill's code and instructions largely match its stated purpose (writing structured logs to Feishu), but there are several inconsistencies and risky defaults (hard-coded fallback credentials, mismatch between registry metadata and SKILL.md environment requirements, and use of an app-level tenant token with wide drive permissions) that warrant caution before installation.
Before installing or running this skill: - Understand the permissions: this skill uses a tenant_access_token (app-level token) and requests drive/docx and permission-granting scopes; that token can access and modify files in your Feishu drive. Only provide FEISHU_APP_ID/FEISHU_APP_SECRET for an app you control and trust. - Replace hard-coded defaults: the repository contains hard-coded fallback App ID/Secret and default folder tokens. Treat those as placeholders; do not use them in production. Supply your own credentials via environment variables or the provided config tool. - Limit scope where possible: if you can, configure the app to only have the minimum drive scope or use a folder-scoped token (if Feishu supports it) rather than broad drive-level permissions. - Review permission-granting behavior: the skill will attempt to add the configured DEFAULT_OWNER_ID as collaborator with full_access on created folders. Verify you want automated full_access grants and test in a non-production account first. - Inspect and run in a safe environment: review code (log.js, log-work.mjs, log-interactive.mjs, feishu-log.js), then run with test credentials or in a test tenant before pointing it at real data. - Avoid storing secrets in shared locations: the tool writes to ~/.openclaw/workspace/.env and ~/.openclaw/feishu-credentials.json; ensure appropriate file permissions and prefer environment variables rather than checked-in files. If you want to proceed, remove or replace any embedded default credentials, verify the app permissions on the Feishu developer console, and test with a limited-scope/test app and a test drive folder first.
Static analysis
No suspicious patterns detected.
