feishu-docx-powerwrite

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional and provides Markdown templates for Feishu Docx generation. No malicious patterns, obfuscation, or unauthorized data access were detected.
  • [COMMAND_EXECUTION]: The scripts/setup.sh file executes a diagnostic command openclaw skills check to verify the local environment. This is a standard operation for the platform and does not include any remote downloads or privilege escalation.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The instructions in SKILL.md and scripts/setup.sh explicitly advise users against hardcoding credentials or sharing tokens, promoting secure secret management practices.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-provided Markdown to write to external documents, it does not involve unsafe interpolation or automated decision-making that could be exploited via indirect injection. It functions as a formatting utility.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 07:45 PM
Security Audit — agent-trust-hub — feishu-docx-powerwrite