Back to skill
Skillv0.1.3

VirusTotal security

Feishu Chat Server API · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

ReviewMar 29, 2026, 12:46 AM
Hash
85ba1297b5e36ab103182689f255f0d4ba3682f017ba2a6e0249ecc237c23582
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: feishu-chat-server-api Version: 0.1.3 The skill acts as a wrapper that instructs the agent to execute remote code via 'uvx' from a GitHub repository (github.com/wodenwang/feishu-extension-skills.git) rather than providing local logic. While this behavior is plausibly intended for its stated purpose of Feishu API management, the pattern of fetching and running remote payloads at runtime is a high-risk execution model that facilitates supply chain attacks. No explicit malicious intent or data exfiltration was found in the provided SKILL.md or _meta.json.
External report
View on VirusTotal