Latest release: v2026.7.1Download zip
Compatibility
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The package purpose is Feishu/Lark workplace chat plus docs, wiki, drive, bitable, and permission tooling; read/write/delete/upload capabilities are high impact but fit that purpose.
Instruction Scope
Bundled skills plainly list mutating actions, local/URL uploads, and permission changes, though the activation text is somewhat broad and the skill docs could state confirmation expectations more strongly.
Install Mechanism
The package is a trusted official @openclaw plugin, source-linked to openclaw/openclaw, uses normal OpenClaw/NPM installation metadata, and shows no postinstall script or hidden installer behavior.
Credentials
The plugin relies on user-configured Feishu credentials and Feishu scopes; the permission tool is disabled by default, while doc/drive/wiki tools are enabled by default when configured.
Persistence & Privilege
Webhook/websocket monitoring, session bindings, and optional dynamic agent creation are expected channel-plugin behavior; dynamic agent creation requires explicit config enablement and config-write permission.
Scan Findings in Context
[SDI-2] expected: URL and local-file uploads are documented Feishu document attachment features, not hidden exfiltration; users should only upload files they intend to send to Feishu.
[SQP-1] expected: Activation wording for docs, drive, permissions, and wiki is broad, but it remains tied to Feishu workflows and does not show deceptive activation.
[SQP-2] expected: Document replace, block deletion, and table deletion are explicit editing actions; the absence of stronger confirmation language is guidance-worthy but not purpose-mismatched.
[SQP-2] expected: Drive create, move, and delete actions are explicitly documented and require configured Feishu access; they are expected for a drive-management tool.
[SQP-1] expected: Permission-management concerns are mitigated by the tool being disabled by default and by the documented add/remove/full_access actions.
[SQP-2] expected: Wiki create, move, rename, and wiki-doc write workflows are disclosed and aligned with knowledge-base management, though operators should confirm targets before use.
Assessment
Install only if you want OpenClaw agents to operate inside Feishu/Lark. Use least-privilege Feishu app scopes, keep the permission tool disabled unless needed, confirm destructive edits or deletes before allowing them, and treat local file upload as sending that file to Feishu.Verification
Tags
OpenClaw Feishu/Lark
Official OpenClaw channel plugin for Feishu and Lark workplace chats. Community maintained by @m1heng.
Install from OpenClaw:
openclaw plugin add @openclaw/feishu
Configure the Feishu/Lark app credentials in OpenClaw, then connect the plugin to the chats where agents should receive and send messages.
