Back to plugin

Security audit

OpenClaw Lark/Feishu Plugin (9.7 Compat)

Security checks for vulnerabilities and agentic risk

Overview

This is a broad but coherent Lark/Feishu integration plugin whose sensitive permissions are mostly disclosed and aligned with its purpose.

Install only if you are comfortable giving this community-maintained plugin access to your Feishu/Lark workspace. Review requested Feishu permissions carefully, avoid broad batch authorization unless needed, confirm destructive operations such as deletes or overwrites, and be careful with local file uploads and calendar times outside China/Asia-Shanghai contexts.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · skills/feishu-channel-rules/SKILL.md (reported line 4)May include surrounding context.

md
---
name: feishu-channel-rules
description: |
  Lark/Feishu channel output rules. Always active in Lark conversations.
alwaysActive: true
---

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · skills/feishu-channel-rules/SKILL.md (reported line 8)May include surrounding context.

md
alwaysActive: true
---

# Lark Output Rules

## Writing Style

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger guidance includes very broad generic terms such as “数据表”, “记录”, and “字段”, which are common across many unrelated productivity, database, and document tasks. This can cause the skill to be invoked outside its intended Feishu Bitable context, increasing the chance of unintended data access, modification, or deletion in workflows where a more specific tool should have been used.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says the skill is 'Always active in Lark conversations' and the manifest sets 'alwaysActive: true', but it does not define any narrower scope, exclusions, or conditions for when the rules should not apply. This creates an overly broad activation condition that could affect routine conversations without clear boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is configured to activate whenever users mention very common task-related terms such as '任务', '待办', '清单', or 'task'. This can cause the agent to invoke task-management capabilities in contexts where the user did not intend an external action, increasing the risk of unintended data access or state-changing operations against Feishu tasks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The upload example shows sending local files into Feishu Bitable without caution about sensitive content, data classification, consent, or third-party transfer implications. In agent use, this can lead to accidental exfiltration of confidential documents or personal data because the example normalizes direct upload from a filesystem path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly instructs the agent to download chat images, files, audio, and video from user conversations, but it provides no warning, consent check, minimization guidance, or handling constraints for potentially sensitive attachments. Because chat attachments often contain confidential or regulated data, this omission can lead to unnecessary collection, transmission, or retention of private content beyond the user's informed expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example explicitly demonstrates batch_delete against records but does not warn that this is a destructive action or recommend confirmation, scoping, preview, or backup before execution. In an agent skill, examples often shape default behavior, so a model may perform irreversible bulk deletions on user data with insufficient friction or validation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation presents create, patch, invite, and reply operations as routine actions without clearly warning that they can send invitations, trigger notifications, change attendee-visible data, and alter users' calendars. In a calendar-management context, this increases the risk of unintended side effects from ambiguous prompts or user misunderstanding, especially because the skill encourages direct execution of state-changing operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill allows users to supply arbitrary image or file URLs and states the system will automatically download and upload them, but the skill-level description does not prominently warn about that network fetch behavior. This can mislead users about where their data goes and can enable abuse such as fetching attacker-controlled resources, exposing internal fetch capability, or unintentionally transferring sensitive content through the platform.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file instructs that these are 'Lark/Feishu channel output rules' and that they are always active in Lark conversations, which imposes a platform-specific output behavior by default. Because the instructions are mandatory and do not offer user choice or opt-in, this may conflict with language/locale policy expectations requiring user preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

自然语言内容全部以中文编写,未见提供其他语言选项、用户语言偏好说明,或明确声明该技能仅面向中文用户/区域。按规则,未经选择而固定单一语言可能构成语言或地区策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The note states that bold text content can only be Chinese or English and cannot include Chinese punctuation or emoji, which imposes a language/locale-related constraint in natural language. The file does not offer an opt-in choice or explain a justified regional policy exception, so this may conflict with language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file presents the skill description and operating instructions solely in Chinese, which can amount to a language/locale constraint without user opt-in. The policy allows locale constraints when explicitly offered as a choice or clearly justified, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

该 markdown 文件包含自然语言与代码示例,L857 的 toLocaleString('zh-CN', ...) 明确固定为中文区域设置。规则 SQP-3 要求避免未经用户选择就强制特定语言或 locale;这里未说明仅适用于中文用户或中国区场景,也未提供可替代的 locale 选项。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file is written entirely in Chinese and does not indicate that the language is optional or region-specific. Under the policy, forcing a specific language without user opt-in can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill hard-codes Asia/Shanghai as the execution timezone, which can cause meetings to be created, modified, or queried at unintended times for users in other locales. In a calendar skill, silent timezone coercion directly affects real-world scheduling and can lead to missed meetings, erroneous availability checks, and unauthorized changes to calendar data at the wrong time.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.