feishu-chat-history
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted chat messages from Feishu group chats to generate summaries. If these messages contain malicious instructions, they could influence the agent's behavior during the summarization or presentation phase.
- Ingestion points: Chat history is fetched from the Feishu IM API (documented in
references/api.md). - Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" warnings when processing the chat content.
- Capability inventory: The skill uses Python scripts to perform network operations and read local configuration files (
~/.openclaw-autoclaw/openclaw.json). - Sanitization: No sanitization or filtering of the message content is specified before the agent processes it for summarization.
- [COMMAND_EXECUTION]: The skill provides Python snippets in
references/api.mdthat useurllib.requestandosto read local configuration files and perform network requests to authentic Feishu endpoints.
Audit Metadata