Back to plugin

Security audit

Feishu/Lark

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Feishu/Lark integration that exposes expected chat, document, wiki, drive, and table tools, with some broad activation wording users should treat carefully.

Install only for workspaces where you intend OpenClaw agents to access Feishu/Lark data. Use least-privilege Feishu app scopes, keep permission tools disabled unless needed, and confirm the target is Feishu/Lark when a request mentions generic docs, folders, or wikis.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation description is broad enough to trigger on common terms like cloud space, folders, files, or comments, which can appear in ordinary conversation outside a clear Feishu Drive intent. Over-broad activation can cause the agent to invoke this skill in unintended contexts, increasing the chance of unnecessary access to private Drive metadata or content and enabling cross-context data exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest says to activate when the user mentions 'a knowledge base, wiki, or wiki link,' which is a broad condition rather than a constrained trigger phrase or narrow context. This can cause unintended invocation during ordinary discussion about documentation or links, especially because no exclusion conditions or negative examples are provided.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation description includes broad trigger phrases like 'cloud docs' and 'docx links', which can match many ordinary requests that are not specifically about Feishu. Over-broad activation can cause the skill to engage in the wrong context, increasing the chance of unintended document access, editing workflows, or tool invocation based on ambiguous user input.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.