feishu-weekly-report

Warn

Audited by Socket on Jul 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose is coherent, and the intended Feishu/OpenClaw relationships appear legitimate, but it reads raw credentials from a local config file and passes the secret via command-line arguments to an unseen shell script. Data access is broad but related to weekly-report generation; the main concern is credential handling and unverifiable script behavior rather than confirmed malicious intent.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Jul 17, 2026, 05:52 AM
Package URL
pkg:socket/skills-sh/LJT-520%2FopenClaw-backup%2Ffeishu-weekly-report%2F@4ca48dbd08ee31dcda8ac8499313bab2b8d142912ec901e5cdd7a31e7eb77d19
Security Audit — socket — feishu-weekly-report