Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The document explicitly tells operators they can send a skill archive to the OpenClaw bot in Feishu chat and that the bot will automatically read and execute its workflow instructions. That normalizes execution of uploaded instruction payloads from chat without requiring provenance checks, review, signing, or sandboxing, which creates an instruction-injection and untrusted code/workflow execution risk.
