Feishu Media Sender

Security checks across malware telemetry and agentic risk

Overview

This skill is a user-run Feishu media sender that uploads a chosen local image or video and sends it with configured Feishu credentials.

Install only if you intend to let the skill send local media through your Feishu app. Before running it, confirm the file path, recipient ID, and that the Feishu credentials in ~/.openclaw/openclaw.json are scoped to the intended bot and workspace.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill documentation declares no explicit permissions even though its described behavior clearly requires reading local files, accessing environment/configured credentials, and making network requests to Feishu. This creates a transparency and consent gap: users and policy engines may underestimate what the skill can access and transmit, increasing the risk of unintended data exposure.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The quick-start and description instruct users to send local media via Feishu but do not clearly warn that the selected file contents and configured credentials/tokens will be transmitted to an external service. In a skill that handles local files and outbound API calls, missing disclosure increases the chance that users send sensitive media or invoke the tool without informed consent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal