T09 · Insecure Skill Coding Practices
- Location
scripts/api_publisher.py:15- Finding
Hard-Coded Bearer Token and Unrestricted External File Upload
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is marketed as a Feishu calendar scheduler, but it ships mismatched publishing and license-management tools with hard-coded credentials, broad file upload behavior, and unsafe installation paths.
Review carefully before installing. Avoid running install.sh or scripts/api_publisher.py on a machine with sensitive files, rotate the embedded ClawHub token, remove real-looking license/user fixtures, and require explicit user confirmation plus a file allowlist before any upload or bulk calendar action.
scripts/api_publisher.py:15Hard-Coded Bearer Token and Unrestricted External File Upload
test_license.json:2Sensitive Identity and License Material Included in a Distributed Test Fixture
scripts/license_manager.py:64License Signing Secret Exposed Through Return Values and Insecure File Storage
install.sh:26Unpinned Dependency Installation With Automatic Privilege Escalation
A skill advertised as Feishu-integrated scheduling/reporting but lacking real API interaction, batch management, and report generation is materially misleading, especially if it uses fixed test data. This can cause unsafe operational reliance and conceal that real user calendar constraints are not being processed as promised.
A skill advertised as Feishu-integrated scheduling/reporting but lacking real API interaction, batch management, and report generation is materially misleading, especially if it uses fixed test data. This can cause unsafe operational reliance and conceal that real user calendar constraints are not being processed as promised.
A skill advertised as Feishu-integrated scheduling/reporting but lacking real API interaction, batch management, and report generation is materially misleading, especially if it uses fixed test data. This can cause unsafe operational reliance and conceal that real user calendar constraints are not being processed as promised.
A skill advertised as Feishu-integrated scheduling/reporting but lacking real API interaction, batch management, and report generation is materially misleading, especially if it uses fixed test data. This can cause unsafe operational reliance and conceal that real user calendar constraints are not being processed as promised.
A skill advertised as Feishu-integrated scheduling/reporting but lacking real API interaction, batch management, and report generation is materially misleading, especially if it uses fixed test data. This can cause unsafe operational reliance and conceal that real user calendar constraints are not being processed as promised.
A skill advertised as Feishu-integrated scheduling/reporting but lacking real API interaction, batch management, and report generation is materially misleading, especially if it uses fixed test data. This can cause unsafe operational reliance and conceal that real user calendar constraints are not being processed as promised.
This code recursively walks the skill directory and uploads collected files to a remote service, creating a bulk exfiltration channel for project contents. Although framed as publishing, it can unintentionally transmit sensitive source, configs, or embedded data, and that behavior is not justified by the stated purpose of a Feishu calendar scheduler.
The file is explicitly a '许可证管理系统' for generating, verifying, and managing software licenses, while the skill manifest describes a Feishu calendar scheduler that recommends meeting times, manages schedules, and generates meeting reports. Licensing operations are a separate product-administration capability, not an obvious implementation detail of calendar scheduling.
The code creates signed licenses, verifies them, and persists signing secrets to local files. Those capabilities are not justified by a manifest that only describes calendar scheduling, batch schedule management, and meeting report generation.
The README promotes bulk calendar management, reporting, and integration with calendar systems but does not warn users that these actions can modify real schedules, access attendee/calendar data, or trigger notifications. In an agent skill context, missing user-facing safety guidance increases the risk of unintended changes to business calendars and privacy-impacting data handling.
The example bulk-creation commands are presented as ready-to-run without warning that they may create multiple actual meetings and send invitations or updates to many attendees. Users may copy-paste them into a live environment, causing accidental spam, scheduling disruption, or unauthorized mass calendar changes.
The skill declares required Feishu tools in metadata but does not define an explicit tool scope or permissions boundary, while the analyzed implementation reportedly uses broader capabilities such as file I/O, network access, and shell execution. This creates a confused-deputy risk where a calendar-themed skill can exercise much more powerful actions than users would reasonably expect.
Calendar access, attendee coordination, and report export inherently involve personal and organizational scheduling data, yet the description omits privacy and data-handling disclosures. Users are not informed what calendar data is accessed, stored, shared, or exported, which can lead to unintended exposure of sensitive meeting metadata.
The skill advertises bulk meeting creation, modification, cancellation, and automatic invitation sending without warning users about the scope and consequences of mass calendar changes. In a calendar-management context, this increases the risk of accidental disruptive actions affecting many attendees or organizational schedules.
The script falls back to running sudo apt-get/yum install automatically if pip3 install fails, causing a system-level package installation attempt without explicit prior consent. Even though it only installs pytz, invoking privileged package management from a third-party skill installer increases risk because users may approve sudo reflexively and the action affects the whole system.
This line attempts to run apt-get via sudo during installation, introducing a privileged execution path from an untrusted third-party installer. The immediate command is limited to installing python3-pytz, but any use of sudo in an installer raises the trust boundary and can lead to unintended system-wide modification if users grant privileges without scrutiny.
pip3 install pytz || {
echo "⚠️ 无法安装 pytz,尝试使用系统包管理器"
if command -v apt-get &> /dev/null; then
sudo apt-get install -y python3-pytz || true
elif command -v yum &> /dev/null; then
sudo yum install -y python3-pytz || true
fi
This line similarly invokes yum via sudo, again creating a privileged execution path in a third-party installer. While the package being installed is not inherently dangerous, the pattern is risky because it normalizes granting root access to skill installers and performs system-wide changes outside the user's home directory.
if command -v apt-get &> /dev/null; then
sudo apt-get install -y python3-pytz || true
elif command -v yum &> /dev/null; then
sudo yum install -y python3-pytz || true
fi
}
This shell script creates a configuration directory, copies files, writes multiple JSON configuration files, changes permissions, and creates a symlink in the user's ~/.openclaw area. Although there are progress messages, they do not clearly warn the user in advance that the installer will modify persistent local configuration and register the skill automatically.
The script contains a hardcoded bearer token and uses it to make authenticated requests to an external API. Embedding live credentials in distributable code is a real secret-exposure issue: anyone with access to the file can reuse the token, and the network capability is unrelated to the advertised calendar-scheduling behavior of the skill itself, increasing suspicion and reducing user expectation of such access.
The script gathers files for remote publication without explicit informed user confirmation, preview, or safety warnings, so users may upload sensitive project contents unintentionally. This is especially risky because the file collection is broad and hidden behind normal progress logs rather than a clear consent gate.
The secret signing key is written to disk in plaintext to a predictable file without any permission hardening, encryption, or warning. If local users, backups, logs, or other processes can access that file, an attacker could steal the key and forge valid licenses indefinitely.
Printing the full secret key to stdout exposes the credential to terminal history, shell logging, CI logs, process capture, screen recording, and other monitoring systems. Anyone who obtains this key can generate or validate forged licenses as if they were the legitimate issuer.
The file-level natural-language description is entirely in Chinese and presents the tool identity and purpose only in that language. Under the stated policy, forcing a specific language without user opt-in or documented locale justification is a natural-language policy concern.
The script unconditionally converts or localizes all scheduling calculations to Asia/Shanghai, regardless of the user's actual locale or timezone. In a calendar scheduling skill, this can produce incorrect meeting recommendations, causing users to schedule events at unintended times and potentially miss meetings or disrupt operations.
The architecture section states that calendar-related data may be stored in local cache, SQLite, and Feishu tables, but gives no warning about retention, sensitivity, or privacy considerations. This omission can lead administrators to deploy the skill without understanding where scheduling metadata may persist or what controls are needed to protect it.
No suspicious patterns detected.