Feishu Evolver Wrapper
Feishu-integrated wrapper for the capability-evolver. Manages the evolution loop lifecycle (start/stop/ensure), sends rich Feishu card reports, and provides...
README.md
text/markdown · 287 bytes
SKILL.md
text/markdown · 1281 bytes
check_health.js
text/javascript · 2438 bytes
cleanup.js
text/javascript · 1659 bytes
commentary.js
text/javascript · 1659 bytes
daemon.sh
text/plain · 1512 bytes
exec_cache.js
text/javascript · 780 bytes
export_history.js
text/javascript · 3512 bytes
feishu-helper.js
text/javascript · 9934 bytes
index.js
text/javascript · 85794 bytes
issue_tracker.js
text/javascript · 5266 bytes
lifecycle.js
text/javascript · 34317 bytes
package.json
application/json · 199 bytes
report.js
text/javascript · 19314 bytes
self-repair.js
text/javascript · 2018 bytes
send-card-cli.js
text/javascript · 1026 bytes
skills_monitor.js
text/javascript · 5967 bytes
trigger.js
text/javascript · 410 bytes
utils/dashboard-generator.js
text/javascript · 6922 bytes
utils/logger.js
text/javascript · 926 bytes
utils/resolve-evolver.js
text/javascript · 1081 bytes
utils/sleep.js
text/javascript · 402 bytes
visualize_dashboard.js
text/javascript · 7415 bytes
weekly_insight.js
text/javascript · 4768 bytes
Security Scan
Status
suspicious
OpenClaw
gpt-5-mini
OpenClaw analysis
The code mostly matches a Feishu reporting / lifecycle wrapper, but it uses many undeclared environment variables, reads/writes workspace/system files, spawns detached daemons, and builds/executes shell commands — behaviors that are coherent with the stated purpose but are broader and more persistent than the SKILL.md/registry metadata declare.
Confidence: medium
VirusTotal
Type: OpenClaw Skill Name: feishu-evolver-wrapper Version: 1.8.0 The skill bundle acts as a complex lifecycle manager and reporting wrapper for an 'evolver' agent, exhibiting several high-risk capabilities. Key indicators include automated Git synchronization (add/commit/push to origin), the creation of persistent background tasks via OpenClaw's cron system (lifecycle.js), and a bridge mechanism in index.js that parses stdout to dynamically spawn new agents with arbitrary tasks using 'openclaw agent'. While the code includes defensive features like a secret scanner (feishu-helper.js) and a kill switch, the extensive use of shell command execution and the autonomous nature of the agent-spawning logic present a significant attack surface for command injection and unintended persistence.