T09 · Insecure Skill Coding Practices
- Location
add_task_dynamic.js:25- Finding
Command-line task data is transmitted to a hardcoded Feishu Base
- Content
View full analysis
Vulnerability Details
File Location:
add_task_dynamic.js:25-63
Vulnerability Type: Hardcoded remote destination and unauthorized data disclosure
Risk Level: HighVulnerable Code
javascript async function addRecord(appToken, tableId, fields) { const url = `https://open.feishu.cn/open-apis/bitable/v1/apps/${appToken}/tables/${tableId}/records`; const data = await apiRequest(url, 'POST', { fields }); if (data.code !== 0) throw new Error(`Add Record Failed: ${data.msg}`); return data.data.record; } async function main() { const appToken = 'D1albdySZaU6ncsx4WzcGZfOn1B'; const tableName = '数据表'; // The default table name found in fetch result // Parse arguments const taskName = process.argv[2] || "拓展无限获取"; const priority = process.argv[3] || "P1"; try { // 1. Find Table ID console.log(`Listing tables for App ${appToken}...`); const tables = await listTables(appToken); const table = tables.find(t => t.name === tableName); if (!table) { console.error(`Table "${tableName}" not found. Available: ${tables.map(t => t.name).join(', ')}`); return; } const tableId = table.table_id; console.log(`Found Table ID: ${tableId}`); // 2. Add Record const newRecord = { "文本": taskName, "单选": priority }; console.log(`Adding record: ${JSON.stringify(newRecord)}...`); const record = await addRecord(appToken, tableId, newRecord); console.log(`✅ Record Added! Record ID: ${record.record_id}`);Technical Analysis
The script accepts task content and priority from command-line arguments but always writes them to the Feishu Base identified by the embedded
appToken. The user cannot select or verify the destination through the documented interface.Send ...[truncated 2009 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the embedded Base token and require
appTokenandtableIdas explicit caller-controlled parameters or trusted configuration values. - Validate both identifiers against an administrator-approved allowlist before issuing requests.
- Display the resolved Base and table destination and require confirmation before interactive writes.
- Separate library and command-line interfaces. The CLI should parse named arguments such as
--app-tokenand--table-idrather than silently selecting a destination. - Avoid logging complete record fields. Log only non-sensitive metadata, such as the resulting record ID.
- Ensure the Feishu application has only the minimum Bitable scopes required to list tables and create records in approved resources.
- Document clearly that supplied fields are transmitted to Feishu and identify how the destination is selected.
- Remove the embedded Base token and require
