feishu-group-welcome
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements standard secret management by reading Feishu API credentials (FEISHU_APP_ID, FEISHU_APP_SECRET) from environment variables or a local configuration file at ~/.openclaw/.env. This follows established security best practices for automation tools.
- [SAFE]: All network requests are made to official and well-known Feishu API endpoints (open.feishu.cn) to fetch group members and send welcome messages.
- [SAFE]: The code behavior aligns perfectly with the stated purpose of automating group welcome notifications, with no hidden or suspicious functionality.
Audit Metadata