T09 · Insecure Skill Coding Practices
- Location
scripts/imap_idle.py:35- Finding
Credentials Are Configured Directly in Source Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This email-to-Feishu notifier is coherent in purpose, but it handles sensitive mailbox content and credentials with incomplete disclosure and weak containment.
Review before installing. Use this only for mailboxes where forwarding excerpts to Feishu is acceptable, avoid putting real secrets directly in the script, restrict file permissions on generated logs and notification JSON, and consider disabling body previews or limiting monitored senders/folders.
scripts/imap_idle.py:35Credentials Are Configured Directly in Source Code
scripts/imap_idle.py:108Sensitive Email Content Is Retained in Plaintext with Default File Permissions
scripts/imap_idle.py:26Third-Party Dependency Is Installed Without Version or Integrity Pinning
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
FEISHU_APP_SECRET = "******"
FEISHU_USER_ID = "******"
def get_feishu_token() -> Optional[str]:
"""获取飞书 access token"""
import urllib.request
try:
url = "https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal"
The skill documents behavior that reads mailbox data, writes notification files to disk, and sends data over the network, but it does not declare any tool scope or permissions. This creates a transparency and containment problem: users and reviewers cannot easily see the skill’s operational boundaries, increasing the chance of overprivileged or unexpected data access during execution.
The skill states that it forwards sender information, subject lines, and a message summary to Feishu and stores notifications locally, but it does not present a clear privacy warning or data-handling notice. Because email metadata and excerpts may contain sensitive personal or business information, users may unknowingly enable external transmission and local persistence of confidential content.
The script persists email-derived data locally in both a JSON file and log file, including sender, subject, UID, timestamps, and potentially body excerpts. This expands data exposure beyond the advertised real-time forwarding behavior and creates additional confidentiality and retention risk if the host is shared, compromised, or backups are accessible.
The code extracts message body text or HTML-derived text and includes it in downstream processing, ultimately forwarding content excerpts to Feishu and storing them locally. Forwarding message content, even truncated, materially increases the sensitivity of the data handled and may leak secrets, OTPs, personal data, or confidential business information.
The script sends email details, including body summaries, to a third-party messaging platform without any interactive consent, warning, or in-script disclosure. In the context of an email-listening skill, this is especially sensitive because incoming mail often contains credentials, personal data, financial details, and internal business content; exfiltration to another platform broadens the trust boundary and compliance exposure.
The user-facing instructions and description are entirely in Chinese, and the file does not offer an alternative language or indicate that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.
The module description and user-facing log/error strings are written exclusively in Chinese, with no indication that the skill is region-specific or that another language can be selected. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.
No suspicious patterns detected.