Bundle Pluginsource linkedVerified

Feishu/Larkv2026.7.1

OpenClaw Feishu/Lark channel plugin for chats and workplace tools (community maintained by @m1heng).

@openclaw/feishu·runtime feishu·by @openclaw
openclaw bundles install clawhub:@openclaw/feishu
Latest release: v2026.7.1Download zip

Compatibility

Built With Open Claw Version
2026.7.1
Min Gateway Version
>=2026.5.29
Plugin Api Range
>=2026.7.1
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
The package purpose is Feishu/Lark workplace chat plus docs, wiki, drive, bitable, and permission tooling; read/write/delete/upload capabilities are high impact but fit that purpose.
Instruction Scope
Bundled skills plainly list mutating actions, local/URL uploads, and permission changes, though the activation text is somewhat broad and the skill docs could state confirmation expectations more strongly.
Install Mechanism
The package is a trusted official @openclaw plugin, source-linked to openclaw/openclaw, uses normal OpenClaw/NPM installation metadata, and shows no postinstall script or hidden installer behavior.
Credentials
The plugin relies on user-configured Feishu credentials and Feishu scopes; the permission tool is disabled by default, while doc/drive/wiki tools are enabled by default when configured.
Persistence & Privilege
Webhook/websocket monitoring, session bindings, and optional dynamic agent creation are expected channel-plugin behavior; dynamic agent creation requires explicit config enablement and config-write permission.
Scan Findings in Context
[SDI-2] expected: URL and local-file uploads are documented Feishu document attachment features, not hidden exfiltration; users should only upload files they intend to send to Feishu.
[SQP-1] expected: Activation wording for docs, drive, permissions, and wiki is broad, but it remains tied to Feishu workflows and does not show deceptive activation.
[SQP-2] expected: Document replace, block deletion, and table deletion are explicit editing actions; the absence of stronger confirmation language is guidance-worthy but not purpose-mismatched.
[SQP-2] expected: Drive create, move, and delete actions are explicitly documented and require configured Feishu access; they are expected for a drive-management tool.
[SQP-1] expected: Permission-management concerns are mitigated by the tool being disabled by default and by the documented add/remove/full_access actions.
[SQP-2] expected: Wiki create, move, rename, and wiki-doc write workflows are disclosed and aligned with knowledge-base management, though operators should confirm targets before use.
Assessment
Install only if you want OpenClaw agents to operate inside Feishu/Lark. Use least-privilege Feishu app scopes, keep the permission tool disabled unless needed, confirm destructive edits or deletes before allowing them, and treat local file upload as sending that file to Feishu.

Verification

Tier
source linked
Scope
artifact only
Summary
Validated package structure and linked the release to source metadata.
Commit
2d2ddc43d0dc
Tag
refs/tags/v2026.7.1
Provenance
No
Scan status
clean

Tags

alpha
2026.5.19-alpha.1
beta
2026.7.2-beta.3
latest
2026.7.1

OpenClaw Feishu/Lark

Official OpenClaw channel plugin for Feishu and Lark workplace chats. Community maintained by @m1heng.

Install from OpenClaw:

openclaw plugin add @openclaw/feishu

Configure the Feishu/Lark app credentials in OpenClaw, then connect the plugin to the chats where agents should receive and send messages.