Openclaw Xiaohongshu Ops

Security checks across malware telemetry and agentic risk

Overview

This appears to be a Feishu publishing workflow skill, but its documented delete capability lacks clear confirmation guidance.

Review before installing. Use it only if you understand which Feishu workspace or publishing artifacts it can modify, and require the agent to preview exact targets before any delete or publish action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill instructs the agent to read files, use bundled scripts, and run a workflow that implies shell, file read/write, and possibly environment access, but it does not declare those permissions explicitly. This creates a permission-transparency gap: reviewers and enforcement layers may underestimate the skill's operational reach, increasing the risk of unintended file access, script execution, or secret exposure in a content-publishing workflow.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documented deletion command enables a destructive action but provides no warning, confirmation requirement, or guidance on verification before execution. In this skill's context, which manages publishing workflows and content artifacts, an ambiguous or accidental delete request could remove the wrong post or review artifact and cause operational loss.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal