Back to skill

Security audit

飞书创建云文档

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documented Feishu document-creation helper with persistent workspace writes, but I found no hidden execution, exfiltration, or deceptive behavior.

Install only if you want the agent to create persistent Feishu documents. For sensitive content, specify the target folder or wiki explicitly, and use only trusted public image/file URLs because referenced media may be fetched and uploaded into your Feishu workspace.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The entire skill description and operational guidance are written as mandatory Chinese-language instructions for document creation, with no indication that users may choose another language or locale. Under the policy, a skill that effectively enforces a specific language without user opt-in should be flagged unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill creates new documents in the user's Feishu workspace and defaults to the personal root folder when no destination is provided, but it does not clearly warn about this side effect near the parameter/behavior description. This can cause unintended writes, workspace clutter, or accidental placement of sensitive content in the wrong location if a user or downstream agent assumes the action is non-persistent or destination-scoped by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that remote image/file URLs are automatically downloaded and uploaded into Feishu, but it does not frame this as a privacy/security warning. That behavior can leak user access patterns, import unreviewed third-party content into the workspace, and cause sensitive external resources to be copied into Feishu without the user fully understanding the transfer.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.