Back to skill

Security audit

feishu-attendance

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it needs review because it handles sensitive Feishu attendance data while storing employee records in plaintext and has an unsafe cache path bug.

Review this skill before installing in a real workspace. It should be limited to an approved Feishu bot with the documented scopes, run first with --dry-run, and ideally fixed to validate dates strictly, cache only minimal employee fields, set owner-only cache permissions, and document data retention and notification policy.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:32
Finding

Unvalidated date input enables cache path traversal

Content
View full analysis
"2026-01-27" const currentYear = getCST().getFullYear(); const shortDateMatch = dateStr.match(/^(\d{1,2})[.-](\d{1,2})$/); if (shortDateMatch) { const month = shortDateMatch[1].padStart(2, '0'); const day = shortDateMatch[2].padStart(2, '0'); dateStr = `${currentYear}-${month}-${day}`; console.log(`Auto-completed date input "${argv.date}" to: ${dateStr}`); } const dateInt = parseInt(dateStr.replace(/-/g, ''), 10); ``` ### Technical Analysis The `--date` command-line value is incorporated directly into a filename passed to `path.join()`. Only short dates matching the optional shorthand expression are normalized. All other strings, including strings containing `/`, `\`, and `..` path components, remain unchanged. The fixed `holiday_` prefix does not prevent traversal when a supplied value contains an initial ordinary component followed by parent-directory components, such as `x/../../../target`. After path normalization, the resulting path may escape `CACHE_DIR`. The read operation is attempted immediately when the derived file exists. The parsed data is subsequently treated as holiday API data. The write operation is conditional on the ...[truncated 1681 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
index.js:8
Finding

Complete Feishu user records are cached in plaintext with implicit filesystem permissions

Content
View full analysis
Remediation
View remediation
({ name, user_id, open_id })); ``` 2. Create the cache directory with owner-only access: ```js fs.mkdirSync(CACHE_DIR, { recursive: true, mode: 0o700 }); ``` 3. Write cache files with owner-only permissions: ```js fs.writeFileSync( USER_CACHE_FILE, JSON.stringify(cachedUsers), { mode: 0o600 } ); ``` 4. Correct permissions on existing files because the creation mode does not repair an already existing permissive file: ```js fs.chmodSync(CACHE_DIR, 0o700); fs.chmodSync(USER_CACHE_FILE, 0o600); ``` 5. Delete expired cache files rather than merely bypassing them. 6. Use atomic writes through an owner-only temporary file followed by `renameSync()` to avoid partial cache content. 7. Document the cached fields, retention period, storage location, and deletion behavior. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

If the implementation mainly performs Feishu authentication/token retrieval without actual attendance analysis or reporting logic, the skill's stated purpose is materially misleading. Hidden or unexplained authentication flows are risky because they can normalize granting sensitive platform credentials to a skill whose real behavior is opaque or broader than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the implementation mainly performs Feishu authentication/token retrieval without actual attendance analysis or reporting logic, the skill's stated purpose is materially misleading. Hidden or unexplained authentication flows are risky because they can normalize granting sensitive platform credentials to a skill whose real behavior is opaque or broader than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the implementation mainly performs Feishu authentication/token retrieval without actual attendance analysis or reporting logic, the skill's stated purpose is materially misleading. Hidden or unexplained authentication flows are risky because they can normalize granting sensitive platform credentials to a skill whose real behavior is opaque or broader than advertised.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill metadata does not declare a tool scope such as allowed tools or equivalent execution boundaries, even though the implementation is described as using environment access and network calls. This creates an authorization and review gap: operators cannot clearly see or constrain what the skill may access, which increases the risk of unintended external communication or secret exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill description says it notifies employees and reports attendance abnormalities to an admin, but it provides no privacy, consent, or user-impact warning. Because attendance status is sensitive employee data, silent notification and reporting workflows can cause privacy harm, labor-policy violations, or inappropriate automated actions if users and administrators are not clearly informed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The function fetches all users from the Feishu contact API, which transmits organizational directory data over the network. While errors are logged, there is no confirmation prompt, user-facing notice, or explanatory comment/docstring warning that this sensitive data collection occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This function sends batches of user IDs and dates to the attendance API and retrieves employee attendance task data, which is sensitive personnel information. The code logs failures but does not provide a confirmation prompt, visible disclosure, or explanatory comment/docstring warning about accessing and transmitting attendance data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The function sends messages to users or chats via the Feishu messaging API, which is an external network action affecting other recipients. There is no confirmation, visible print/log for users, or descriptive comment/docstring explaining that the skill will transmit provided content to external recipients.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency uses a caret version range, which allows npm to install newer compatible releases automatically. While common in JavaScript projects, this weakens supply-chain reproducibility and can introduce vulnerable or malicious upstream changes without an explicit code update in this skill.

Content

Scanner excerpt · package.json (reported line 10)May include surrounding context.

json
"test": "echo \"Error: no test specified\" && exit 1"
  },
  "dependencies": {
    "dotenv": "^16.3.1",
    "node-fetch": "^2.7.0",
    "yargs": "^17.7.2"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The node-fetch dependency is specified with a caret range, so future installs may resolve to different package versions. In a skill that likely handles attendance data and may call external APIs, non-reproducible dependency resolution increases supply-chain risk if an upstream release is compromised or introduces a security flaw.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
},
  "dependencies": {
    "dotenv": "^16.3.1",
    "node-fetch": "^2.7.0",
    "yargs": "^17.7.2"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The yargs package is not pinned to an exact version, allowing semver-compatible updates during installation. This creates a supply-chain exposure because the deployed code can change over time even when the skill source does not, potentially introducing unexpected behavior or vulnerabilities.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
"dependencies": {
    "dotenv": "^16.3.1",
    "node-fetch": "^2.7.0",
    "yargs": "^17.7.2"
  }
}