@dingtalk-real-ai/dingtalk-connector
Official OpenClaw DingTalk channel plugin | 钉钉官方 OpenClaw 插件
Security Findings
6Recently created account
Account was 0d old when repo was created
Remote code execution pipe
Downloads and pipes to shell: curl -fsSL https://github.com/open-dingtalk/dingtalk-workspace-cli/releases/latest/download/install.sh | sh
skills/dingtalk-troubleshoot
External binary download
Prerequisite downloads from non-standard source: https://github.com/open-dingtalk/dingtalk-workspace-cli/releases/latest/download/install.sh
skills/dingtalk-troubleshoot
Low-provenance referenced GitHub repo
Referenced repo open-dingtalk/dingtalk-workspace-cli not found (deleted / renamed / private): https://github.com/open-dingtalk/dingtalk-workspace-cli/releases/latest/download/install.sh
skills/dingtalk-troubleshoot
Unreachable / dead referenced source
Referenced executable source is returning 404 (resource gone): https://github.com/open-dingtalk/dingtalk-workspace-cli/releases/latest/download/install.sh
skills/dingtalk-troubleshoot
Workflow makes outbound network call
[.github/workflows/ai-fix-and-test.yml] curl -s -X POST https://api.openai.com/v1/chat/completions
Contents
3 skills bundled by this extension
dingtalk-troubleshoot
skill
Why it’s high risk
Remote code execution pipe
Downloads and pipes to shell: curl -fsSL https://github.com/open-dingtalk/dingtalk-workspace-cli/releases/latest/download/install.sh | sh
+3 more findings
dingtalk-channel-rules
skill
dws-cli
skill
Editions
1- 0.8.20Scanned Aug 4, 2026, 03:33 PM10High Risk