screenshot_to_feishu

Warn

Audited by Socket on Feb 20, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/screenshot-to-feishu.sh

The code itself is not obfuscated and contains no clear code-level malware (no reverse shell, no eval, no obfuscated payloads). However, it performs automatic screenshot capture and uploads the image to a remote Feishu target using a hardcoded recipient ID. That behavior constitutes potential privacy-invasive data exfiltration: if misused or run without user consent, it can leak sensitive screen contents. Review deployment context and ensure explicit user consent and secure handling of screenshots before use.

Confidence: 80%Severity: 50%
Audit Metadata
Analyzed At
Feb 20, 2026, 03:24 AM
Package URL
pkg:socket/skills-sh/tclawde%2Fopenclaw-skills-user%2Fscreenshot-to-feishu%2F@16b3f795200a4c1fcbde8642ba9118d75e62906b