feishu-chat-history

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted chat messages from Feishu group chats to generate summaries. If these messages contain malicious instructions, they could influence the agent's behavior during the summarization or presentation phase.
  • Ingestion points: Chat history is fetched from the Feishu IM API (documented in references/api.md).
  • Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" warnings when processing the chat content.
  • Capability inventory: The skill uses Python scripts to perform network operations and read local configuration files (~/.openclaw-autoclaw/openclaw.json).
  • Sanitization: No sanitization or filtering of the message content is specified before the agent processes it for summarization.
  • [COMMAND_EXECUTION]: The skill provides Python snippets in references/api.md that use urllib.request and os to read local configuration files and perform network requests to authentic Feishu endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:23 AM
Security Audit — agent-trust-hub — feishu-chat-history