Back to skill

Security audit

Tmp.SnUxDV6npc

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to provide disclosed Tencent Meeting and Feishu task-board automation without hidden or destructive behavior, though its install and credential handling deserve care.

Install only if you are comfortable letting the agent use your Tencent Meeting session and a Feishu enterprise app to read meeting data and write task-board records. Prefer pinning or reviewing the tmeet npm package before global installation, limit the Feishu app to the intended Bitable, keep the ~/.config credential files mode 600, and require explicit confirmation before any meeting or task-board write action.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:56
Finding

Unpinned Global Installation of a Mutable Third-Party Package

Content
View full analysis
Remediation
View remediation
``` 2. Document the expected npm registry and package publisher. 3. Record and verify package integrity metadata or a trusted digest where the installation workflow permits it. 4. Prefer a project-local installation over a global installation, then invoke the binary through a controlled package script or `npx --no-install`. 5. Review package lifecycle scripts and release notes before updating the pinned version. 6. Establish an explicit dependency-update process so new releases are reviewed before the documentation is changed. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/feishu_taskboard.py:102
Finding

Sensitive Credential Files Are Restricted Only After Their Contents Are Written

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个端到端“科学开会”系统,核心能力覆盖会议前中后多个阶段,并集成腾讯会议与飞书;但所给代码片段实际上只是其中一个子模块——飞书多维表格任务中控台。它的行为集中在对飞书 bitable 的任务记录增删查改与字段初始化,没有看到任何会议创建、纪要抓取、转写分析、ROI 计算、原则检查或 tmeet 调用。因此,如果将这段代码视为对整体技能描述的实现,则描述明显夸大了实际功能。虽然描述中确实提到“任务中控台(飞书多维表格)”,与代码部分吻合,但代码只覆盖该很小的一部分,无法支撑整体声明的主要用途。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill clearly instructs use of shell commands, networked services, and local credential/config file writes, but it declares no explicit tool scope or permission boundaries. In an agent environment, this can enable overbroad execution authority and make sensitive actions like meeting control, credential handling, and remote API access occur without an auditable least-privilege contract.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The display name, description, trigger phrases, instructions, examples, and expected outputs are all written in Chinese, and the skill does not indicate that users may choose another language. This can violate a language/locale policy when a skill implicitly forces one language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match ordinary conversation about meetings, including generic phrases like creating meetings, reviewing meetings, or wanting to hold a meeting. Overbroad activation can cause the skill to run unexpectedly, increasing the chance of unintended access to meeting data, transcripts, contact search, or task-board write operations in contexts where the user did not intend to invoke this automation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 305)May include surrounding context.

md
update  --record-id <id> --status <状态>     改状态(Hermes 同步用;人勾选在飞书里点)
  fields                                        打印当前字段结构

配置文件:~/.config/feishu-task-console.json  (chmod 600,含 app_id/app_secret)
  {"app_id":"...","app_secret":"...","app_token":"...","table_id":"..."}

凭证获取:open.feishu.cn 创建企业自建应用 → 开通 bitable:app / bitable:record 权限

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 429)May include surrounding context.

md
update  --record-id <id> --status <状态>     改状态(Hermes 同步用;人勾选在飞书里点)
  fields                                        打印当前字段结构

配置文件:~/.config/feishu-task-console.json  (chmod 600,含 app_id/app_secret)
  {"app_id":"...","app_secret":"...","app_token":"...","table_id":"..."}

凭证获取:open.feishu.cn 创建企业自建应用 → 开通 bitable:app / bitable:record 权限

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/feishu_taskboard.py (reported line 21)May include surrounding context.

python
update  --record-id <id> --status <状态>     改状态(Hermes 同步用;人勾选在飞书里点)
  fields                                        打印当前字段结构

配置文件:~/.config/feishu-task-console.json  (chmod 600,含 app_id/app_secret)
  {"app_id":"...","app_secret":"...","app_token":"...","table_id":"..."}

凭证获取:open.feishu.cn 创建企业自建应用 → 开通 bitable:app / bitable:record 权限

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, CLI help text, status values, and user-facing messages are all hard-coded in Chinese, which imposes a specific language/locale on users. The file does not indicate that Chinese is optional or that users may choose another language, so it matches the language-policy concern for natural-language constraints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.