Back to skill

Security audit

Feishu Calendar Intelligent Scheduler

Security checks for vulnerabilities and agentic risk

Overview

The skill is marketed as a Feishu calendar scheduler, but it ships mismatched publishing and license-management tools with hard-coded credentials, broad file upload behavior, and unsafe installation paths.

Review carefully before installing. Avoid running install.sh or scripts/api_publisher.py on a machine with sensitive files, rotate the embedded ClawHub token, remove real-looking license/user fixtures, and require explicit user confirmation plus a file allowlist before any upload or bulk calendar action.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/api_publisher.py:15
Finding

Hard-Coded Bearer Token and Unrestricted External File Upload

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
test_license.json:2
Finding

Sensitive Identity and License Material Included in a Distributed Test Fixture

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/license_manager.py:64
Finding

License Signing Secret Exposed Through Return Values and Insecure File Storage

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
install.sh:26
Finding

Unpinned Dependency Installation With Automatic Privilege Escalation

Content
View full analysis
/dev/null; then sudo apt-get install -y python3-pytz || true elif command -v yum &> /dev/null; then sudo yum install -y python3-pytz || true fi } ``` ### Technical Analysis The installer retrieves `pytz` without pinning a version, verifying hashes, or creating an isolated environment. Package resolution therefore depends on the user's active pip configuration, package index, proxy, and current upstream state. If pip installation fails, the script automatically invokes `sudo` and modifies system-managed packages. This exceeds the minimum privileges needed by a local scheduling script and combines package retrieval with privileged system modification. The fallback also suppresses installation failure with `|| true`, potentially leaving an inconsistent or partially configured installation. No evidence shows that `pytz` itself is malicious. The vulnerability is the unverified and privileged dependency installation process. ### Attack Path 1. A user runs `install.sh`. 2. The script executes the active `pip3` command using the user's configured package index and resolver. 3. An attacker who controls or influences that index, DNS path, proxy configuration, or package resolution supplies a malicious or compromised dependency release. 4. Package build or installation hooks execute under the installing user's account. 5. If pip fails, the script requests `sudo` and modifies global system packages through `apt-get` or `yum`. 6. A compromised repository or package-manager path could consequently affect the entire host. ### Impact Assessment A compromised pip dependency can execute code with the invoking user's privileges and alter the global Python environment. Th ...[truncated 230 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A skill advertised as Feishu-integrated scheduling/reporting but lacking real API interaction, batch management, and report generation is materially misleading, especially if it uses fixed test data. This can cause unsafe operational reliance and conceal that real user calendar constraints are not being processed as promised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill advertised as Feishu-integrated scheduling/reporting but lacking real API interaction, batch management, and report generation is materially misleading, especially if it uses fixed test data. This can cause unsafe operational reliance and conceal that real user calendar constraints are not being processed as promised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill advertised as Feishu-integrated scheduling/reporting but lacking real API interaction, batch management, and report generation is materially misleading, especially if it uses fixed test data. This can cause unsafe operational reliance and conceal that real user calendar constraints are not being processed as promised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A skill advertised as Feishu-integrated scheduling/reporting but lacking real API interaction, batch management, and report generation is materially misleading, especially if it uses fixed test data. This can cause unsafe operational reliance and conceal that real user calendar constraints are not being processed as promised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A skill advertised as Feishu-integrated scheduling/reporting but lacking real API interaction, batch management, and report generation is materially misleading, especially if it uses fixed test data. This can cause unsafe operational reliance and conceal that real user calendar constraints are not being processed as promised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A skill advertised as Feishu-integrated scheduling/reporting but lacking real API interaction, batch management, and report generation is materially misleading, especially if it uses fixed test data. This can cause unsafe operational reliance and conceal that real user calendar constraints are not being processed as promised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code recursively walks the skill directory and uploads collected files to a remote service, creating a bulk exfiltration channel for project contents. Although framed as publishing, it can unintentionally transmit sensitive source, configs, or embedded data, and that behavior is not justified by the stated purpose of a Feishu calendar scheduler.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file is explicitly a '许可证管理系统' for generating, verifying, and managing software licenses, while the skill manifest describes a Feishu calendar scheduler that recommends meeting times, manages schedules, and generates meeting reports. Licensing operations are a separate product-administration capability, not an obvious implementation detail of calendar scheduling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code creates signed licenses, verifies them, and persists signing secrets to local files. Those capabilities are not justified by a manifest that only describes calendar scheduling, batch schedule management, and meeting report generation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README promotes bulk calendar management, reporting, and integration with calendar systems but does not warn users that these actions can modify real schedules, access attendee/calendar data, or trigger notifications. In an agent skill context, missing user-facing safety guidance increases the risk of unintended changes to business calendars and privacy-impacting data handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example bulk-creation commands are presented as ready-to-run without warning that they may create multiple actual meetings and send invitations or updates to many attendees. Users may copy-paste them into a live environment, causing accidental spam, scheduling disruption, or unauthorized mass calendar changes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares required Feishu tools in metadata but does not define an explicit tool scope or permissions boundary, while the analyzed implementation reportedly uses broader capabilities such as file I/O, network access, and shell execution. This creates a confused-deputy risk where a calendar-themed skill can exercise much more powerful actions than users would reasonably expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Calendar access, attendee coordination, and report export inherently involve personal and organizational scheduling data, yet the description omits privacy and data-handling disclosures. Users are not informed what calendar data is accessed, stored, shared, or exported, which can lead to unintended exposure of sensitive meeting metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises bulk meeting creation, modification, cancellation, and automatic invitation sending without warning users about the scope and consequences of mass calendar changes. In a calendar-management context, this increases the risk of accidental disruptive actions affecting many attendees or organizational schedules.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script falls back to running sudo apt-get/yum install automatically if pip3 install fails, causing a system-level package installation attempt without explicit prior consent. Even though it only installs pytz, invoking privileged package management from a third-party skill installer increases risk because users may approve sudo reflexively and the action affects the whole system.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

This line attempts to run apt-get via sudo during installation, introducing a privileged execution path from an untrusted third-party installer. The immediate command is limited to installing python3-pytz, but any use of sudo in an installer raises the trust boundary and can lead to unintended system-wide modification if users grant privileges without scrutiny.

Content

Scanner excerpt · install.sh (reported line 31)May include surrounding context.

sh
pip3 install pytz || {
    echo "⚠️  无法安装 pytz,尝试使用系统包管理器"
    if command -v apt-get &> /dev/null; then
        sudo apt-get install -y python3-pytz || true
    elif command -v yum &> /dev/null; then
        sudo yum install -y python3-pytz || true
    fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

This line similarly invokes yum via sudo, again creating a privileged execution path in a third-party installer. While the package being installed is not inherently dangerous, the pattern is risky because it normalizes granting root access to skill installers and performs system-wide changes outside the user's home directory.

Content

Scanner excerpt · install.sh (reported line 33)May include surrounding context.

sh
if command -v apt-get &> /dev/null; then
        sudo apt-get install -y python3-pytz || true
    elif command -v yum &> /dev/null; then
        sudo yum install -y python3-pytz || true
    fi
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell script creates a configuration directory, copies files, writes multiple JSON configuration files, changes permissions, and creates a symlink in the user's ~/.openclaw area. Although there are progress messages, they do not clearly warn the user in advance that the installer will modify persistent local configuration and register the skill automatically.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script contains a hardcoded bearer token and uses it to make authenticated requests to an external API. Embedding live credentials in distributable code is a real secret-exposure issue: anyone with access to the file can reuse the token, and the network capability is unrelated to the advertised calendar-scheduling behavior of the skill itself, increasing suspicion and reducing user expectation of such access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script gathers files for remote publication without explicit informed user confirmation, preview, or safety warnings, so users may upload sensitive project contents unintentionally. This is especially risky because the file collection is broad and hidden behind normal progress logs rather than a clear consent gate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The secret signing key is written to disk in plaintext to a predictable file without any permission hardening, encryption, or warning. If local users, backups, logs, or other processes can access that file, an attacker could steal the key and forge valid licenses indefinitely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Printing the full secret key to stdout exposes the credential to terminal history, shell logging, CI logs, process capture, screen recording, and other monitoring systems. Anyone who obtains this key can generate or validate forged licenses as if they were the legitimate issuer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file-level natural-language description is entirely in Chinese and presents the tool identity and purpose only in that language. Under the stated policy, forcing a specific language without user opt-in or documented locale justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script unconditionally converts or localizes all scheduling calculations to Asia/Shanghai, regardless of the user's actual locale or timezone. In a calendar scheduling skill, this can produce incorrect meeting recommendations, causing users to schedule events at unintended times and potentially miss meetings or disrupt operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The architecture section states that calendar-related data may be stored in local cache, SQLite, and Feishu tables, but gives no warning about retention, sensitivity, or privacy considerations. This omission can lead administrators to deploy the skill without understanding where scheduling metadata may persist or what controls are needed to protect it.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.