Back to skill

Security audit

飞书日历管理工具

Security checks for vulnerabilities and agentic risk

Overview

This calendar skill is transparent about its behavior, but it defaults invited attendees to being able to edit events and manage participants.

Review whether your organization wants meeting attendees, groups, rooms, or external email invitees to receive edit rights by default. Use narrower attendee permissions unless collaborators explicitly need to modify the event or manage participants, and confirm the fixed Asia/Shanghai timezone matches your calendar workflow.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:51
Finding

Excessive Default Attendee Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 51–60
Vulnerability Type: Excessive default permissions that violate least privilege
Risk Level: Medium

Complete Code Snippet:

markdown
### 2. 参会人权限(attendee_ability)

工具已默认设置 `attendee_ability: "can_modify_event"`,参会人可以编辑日程和管理参与者。

| 权限值 | 能力 |
|--------|------|
| `none` | 无权限 |
| `can_see_others` | 可查看参与人列表 |
| `can_invite_others` | 可邀请他人 |
| `can_modify_event` | 可编辑日程(推荐) |

The policy is reinforced at lines 174 and 177:

markdown
| **参会人看不到其他参会人** | `attendee_ability` 权限不足 | 工具已默认设置 `can_modify_event` |
| **修改日程报权限错误** | 当前用户不是组织者,且日程未设置可编辑权限 | 确保日程创建时设置了 `attendee_ability: "can_modify_event"` |

Technical Analysis

The Skill states that attendee_ability defaults to can_modify_event and recommends this setting generally. This permission allows attendees to edit an event and manage its participants, although ordinary attendance does not require either capability.

The documented availability of narrower settings—none, can_see_others, and can_invite_others—shows that the elevated permission is not technically necessary for all events. Assigning the highest documented attendee permission by default violates the principle of least privilege.

This is especially risky because the Skill supports user, group, meeting-room, and external-email attendee types. An unintended, untrusted, or compromised attendee could receive modification privileges without a separate authorization decision by the organizer.

Attack Path

  1. An organizer creates a calendar event using the Skill.
  2. The tool applies the documented default attendee_ability: "can_modify_event".
  3. An untrusted or compromised account is included as an attendee, directly or through a supported attendee mechanism.
  4. That attendee uses the granted capability to modify event details or manage the participant list.
  5. Other attendees receive or r ...[truncated 824 chars]
Remediation
View remediation

Remediation Suggestions

  1. Change the default attendee_ability to none, or to the narrowest permission necessary for the requested operation.
  2. Require explicit organizer confirmation before assigning can_modify_event.
  3. Do not describe can_modify_event as the generally recommended setting; document it as a high-privilege option for trusted collaborators only.
  4. If attendees only need visibility into the participant list, use can_see_others.
  5. If attendees only need to invite others, use can_invite_others and clearly communicate that capability.
  6. Display a warning before granting modification rights, identifying the affected event and attendees.
  7. Validate attendee identity and type before granting elevated permissions, with particular caution for external addresses and group-based attendees.
  8. Add tests or policy checks that reject implicit can_modify_event assignments unless an explicit authorization flag is present.
  9. Update the troubleshooting guidance at lines 174 and 177 so it does not recommend broad modification privileges as the default solution to visibility or authorization problems.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown explicitly states '时区固定:Asia/Shanghai(UTC+8)', which forces a specific locale/timezone policy for all usage. Under the policy criteria, fixed locale behavior is a violation unless the skill offers user choice or clearly justifies the regional constraint; this file does not provide such opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.