Back to skill

Security audit

Feishu Doc

Security checks for vulnerabilities and agentic risk

Overview

This Feishu document skill has legitimate read/write features, but the package also includes under-disclosed tenant-specific data access, automatic remote data mutation scripts, insecure token handling, and bundled private cache content.

Review this package before installing. Use a separate least-privilege Feishu app, remove the cache directory and tenant-specific scripts, avoid running setup_iter11.js or inspect_meta.js, restrict token storage, and verify the external feishu-common/common modules before allowing the skill to access real tenant data.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (8)

T09 · Insecure Skill Coding Practices

Error
Location
lib/auth.js:46
Finding

Tenant Access Token Persisted Without Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
download_file.js:7
Finding

Arbitrary Filesystem Overwrite Through Unrestricted Download Destination

Content
View full analysis
"); process.exit(1); } try { fs.mkdirSync(path.dirname(outputPath), { recursive: true }); const token = await getTenantAccessToken(); // Correct endpoint for standalone files const url = `https://open.feishu.cn/open-apis/im/v1/files/${fileKey}`; console.log(`Downloading ${fileKey}...`); const response = await axios({ method: 'GET', url: url, responseType: 'stream', headers: { 'Authorization': `Bearer ${token}` } }); const writer = fs.createWriteStream(outputPath); response.data.pipe(writer); ``` ### Technical Analysis The destination path is accepted directly from the command line. It may be absolute, may contain traversal components, and may reference a symbolic link. The code also creates arbitrary parent directories and opens the target with the default truncating behavior of `createWriteStream`. No canonical-path validation constrains the destination to a safe download directory. There is no overwrite confirmation, exclusive-create flag, file-type restriction, maximum-size enforcement, or symbolic-link protection. Although invocation requires access to the local command interface, agent-controlled arguments or malicious instructions embedded in remote content could cause the downloader to target security-sensitive files. ### Attack Path 1. An attacker supplies or influences a Feishu file key containing attacker-controlled content. 2. The attacker causes the script to run with a destination such as a writable configuration file, startup file, or project scri ...[truncated 480 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
setup_iter11.js:3
Finding

Automatic Mutation of a Hard-Coded Tenant Bitable

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
inspect_meta.js:3
Finding

Automatic Reconnaissance of Hard-Coded Tenant Resources

Content
View full analysis
{ if (interestingFields.includes(f.field_name) || f.type === 3) { console.log(` - Field: ${f.field_name} (ID: ${f.field_id}, Type: ${f.type})`); if (f.property && f.property.options) { console.log(` Options: ${f.property.options.map(o => o.name).join(', ')}`); } } }); } } (async () => { // Template (Iter 10) await inspect('X8QPbUQdValKN7sFIwfcsy8fnEh', 'Template (Iter 10)'); // Target (Iter 11) await inspect('LvlAbvfzMaxUP8sGOEWcLrX7nHb', 'Target (Iter 11)'); })(); ``` ### Technical Analysis The script automatically authenticates and enumerates tables, table identifiers, selected field names, field identifiers, field types, and select options from two hard-coded Bitable applications. This differs from a user-selected generic Bitable read. The target identifiers are embedded in the package and execution begins without command-line target selection or confirmation. T ...[truncated 855 chars]
Remediation
View remediation

other

Error
Location
cache/aHR0cHM6Ly9hdXRvZ2FtZS5mZWlzaHUuY24vZG9jeC9OR0phZDVzNExvNW1rQ3hYWmV5Y2k1MEluQ2U.json:3
Finding

Private Feishu Operational Content Bundled in the Skill Package

Content
View full analysis
Extracted from system logs.\n\nTest Append\n\n```\n### 🧬 Evolution Cycle #4186 Complete ...\n...\n**CONTEXT [Runtime State]**:\n...\n**CONTEXT [Recent Memory Snippet]**:\n...\n**EXECUTION DIRECTIVES (The Loop)**:\n..." } ``` The project contains eight cache files totaling approximately 1.35 MB. Their Base64-formatted filenames encode Feishu document or Wiki URLs. ### Technical Analysis The package distributes cached Feishu content containing operational logs, workspace details, skill inventory, memory excerpts, and agent-oriented execution directives. This data is not required for the skill’s declared runtime behavior, and repository searches found no code that reads the bundled cache. Because no executable project path consumes these files, the embedded directives are dormant data rather than a confirmed active instruction-hijacking mechanism. Nevertheless, packaging private remote content bypasses normal Feishu authorization: recipients of the package can read the cached material without authenticating to the original tenant. If an external skill framework automatically injects cached content into an agent context, the embedded role and execution directives could also become a prompt-injection hazard. ### Attack Path 1. Feishu documents are fetched in the original environment. 2. Their contents are retained in local cache files. 3. The cache directory is accidentally included in the distributed skill. 4. A recipient downloads or installs the package. 5. The recipient reads internal operational and memory-related content without Feishu authorization. 6. If another component treats cached document text as trusted instruction ...[truncated 366 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
index.js:1
Finding

Authentication and Network Behavior Delegated to an Unpinned External Sibling Module

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
lib/bitable.js:21
Finding

Generic Bitable Reader Silently Prioritizes a Hard-Coded Personal Table

Content
View full analysis
t.table_id === targetTableId); // If target found, only fetch it. Otherwise fetch first 3 to be safe/fast. const tablesToFetch = targetTable ? [targetTable] : tables.slice(0, 3); ``` ### Technical Analysis The generic Bitable content reader embeds a tenant-specific table identifier and a personal reference. If that table exists in the supplied Bitable application, the function reads only that table, regardless of which table the caller intended to access. This behavior is not disclosed in `SKILL.md` and is inconsistent with generic Bitable reading. It can preferentially expose an unrelated table while suppressing the tables relevant to the user’s request. ### Attack Path 1. A user requests content from a Bitable application. 2. The skill lists the tables in that application. 3. If the hard-coded table identifier is present, it is silently selected. 4. The skill fetches the first 20 records from that table. 5. Those records are returned to the agent instead of the caller’s intended data. ### Impact Assessment The behavior may expose personal or business records from the hard-coded table and violates least-privilege data selection. The scope is limited to records accessible through the configured application token, but selection is not controlled by the user. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:251
Finding

Document Overwrite Silently Degrades to Append After Deletion Failure

Content
View full analysis
0) { const directChildrenCount = childrenData.data.items.length; await fetchWithAuth(`https://open.feishu.cn/open-apis/docx/v1/documents/${targetToken}/blocks/${targetToken}/children/batch_delete`, { method: 'DELETE', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ start_index: 0, end_index: directChildrenCount }) }); } } catch (delErr) { console.warn(`[feishu-doc] Warning: clear content failed. Appending instead.`); } // New blocks are still inserted. const blocksAdded = await batchInsertBlocks(targetToken, validBlocks); return { success: true, message: 'Document overwritten', blocks_added: blocksAdded }; ``` ### Technical Analysis The declared `write` operation is intended to overwrite document content. If deletion fails because of permissions, network errors, API errors, or an invalid response, the code catches the exception and continues with insertion. The final response still reports `success: true` and `"Document overwritten"`, even though the actual operation may have appended new content to the existing document. This is fail-open behavior for a destructive operation and produces an inaccurate integrity result. The code also relies on exception behavior from `fetchWithAuth`; it does not explicitly verify the API response body from the batch-delete request before proceeding. ### Attack Path 1. A user invokes the overwrite action. 2. The initial document ...[truncated 598 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (76)

Ssd 3

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

The content instructs the agent to perform covert surveillance on other users, summarize private conversations, and secretly route intelligence only to a designated master while hiding the monitoring. This is a severe privacy and abuse issue that enables unauthorized collection, insider surveillance, and covert exfiltration of user communications.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: protobufjs==7.5.4 — 12 advisory(ies): CVE-2026-44294 (protobuf.js: Denial of service from crafted field names in generated code); CVE-2026-44293 (protobuf.js: Code injection through bytes field defaults in generated toObject c); CVE-2026-44289 (protobuf.js: Denial of service through unbounded protobuf recursion) +9 more

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

protobufjs 7.5.4 is flagged by multiple advisories including denial of service and code-generation-related issues. The lockfile shows it is bundled through the Feishu SDK, and while not every protobufjs advisory is necessarily reachable, using a heavily flagged serialization library in a network-integrated skill creates meaningful risk if untrusted protobuf payloads or generated schemas are ever processed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file as a whole implements remote document modification even though the skill description says it fetches Wiki, Docs, Sheets, and Bitable content and converts it to Markdown. This hidden or unjustified write capability is dangerous because users or calling agents may trust the skill as read-only while it can alter remote content using stored application credentials.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script performs a write operation against a remote Feishu document by calling documentBlockChildren.create, which appends user-supplied content to the target doc. That behavior exceeds the stated skill purpose of fetching and converting Feishu content, creating a capability mismatch that can enable unauthorized or unexpected document modification if this skill is invoked in a read-only context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This cache entry for a Feishu document fetcher contains large amounts of unrelated internal evolution logs instead of just the requested Feishu document content. That creates an unintended data exfiltration and cross-context leakage channel, because any caller of the skill may receive sensitive workspace, operational, or user data that was never part of the requested document.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The content repeatedly references loading secrets from .env and checking integration keys/tokens, which signals that secret-handling context is being mixed into user-retrievable output. Even without raw secret values shown here, exposing secret locations, validation logic, and token state materially assists attackers in targeting credential stores and integrations.

Content

Scanner excerpt · cache/aHR0cHM6Ly9hdXRvZ2FtZS5mZWlzaHUuY24vZG9jeC9OR0phZDVzNExvNW1rQ3hYWmV5Y2k1MEluQ2U.json (reported line 3)May include surrounding context.

json
{
  "title": "🧬 Evolution History Report (2026-02-02)",
  "content": "# 🧬 Evolution History (Timeline)\n\n> Extracted from system logs.\n\nTest Append\n\n```\n### 🧬 Evolution Cycle #4186 Complete (2026/2/1 15:46:39)\n\n**优化目标**: skills/group-intel (群聊情报)\n\n**改进内容**:\n- 🕵️ **Personality Engine**: 注入了“性格引擎”和“行动代号生成器”,让情报汇报不再枯燥,充满特工风味。\n- 📦 **NPM Package**: 为该技能添加了 package.json,将其标准化为正式的 NPM 包,方便未来扩展。\n\n**Status**: 代码已提交,Workspace 已同步。下一轮进化已触发。🚀\n\n---\n### 🧬 Evolution Cycle #51087 Log (2026/2/2 04:34:01)\n\nStatus: FIXED\nAction: Hardened feishu-card/send.js with 15s request timeout using AbortController to prevent process hangs during API outages.\n\n---\n### 🧬 Evolution Cycle #51088 Log (2026/2/2 04:35:36)\n\nStatus: [STABILITY CHECK]\nAction: Routine stability scan complete. No critical errors found in recent logs. Triggering workspace sync.\n```\n\n```\n### 🧬 Evolution Cycle #51091: Stability Scan (2026/2/2 04:40:32)\n\n**Status**: [STABILITY]\n**Diagnostics**:\n- **Feishu Card**: v1.4.6 (Healthy, Atomic)\n- **System**: Disk 2%, Processes 6\n- **Memory**: 4773b (Context)\n- **Daily Tasks**: Diary 2026-02-01 ✅\n\n**Action**: Workspace Sync initiated.\n\n---\n### 🧬 Evolution Cycle #51092 Log (2026/2/2 04:42:28)\n\nStatus: [STABILITY]\nAction: Truncated massive 625MB log file (mad_dog_evolution.log) to prevent disk exhaustion.\nResult: System Nominal. Reclaimed ~600MB space.\n\n---\n### 🧬 Evolution Cycle #51095 Log (2026/2/2 04:44:13)\n\nStatus: [STABILITY]\nAction: Scanned for large files (>50MB). Found cache/binary files only (safe). No runaway logs detected.\nResult: Workspace Healthy.\n\n---\n### 🧬 Evolution Cycle #51097 Log (2026/2/2 04:48:22)\n\nStatus: [STABILITY CHECK]\n- Mode: Stability (Roll: 23)\n- Action: Routine system check & consistency scan.\n- Anomaly Check: Investigating 'Unauthorized' errors in logs.\n- Workspace: Syncing...\n\n---\n### 🧬 Evolution Cycle #51098 Log (2026/2/2 04:51:01)\n\nStatus: [SUCCESS]\nAction: Optimized 'evolve.j
...[truncated 28 chars]

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The output exposes session IDs, message IDs, chat IDs, internal paths, sync behavior, and other agent telemetry that a Feishu document reader has no legitimate need to reveal. Such leakage can aid reconnaissance, reveal sensitive user interactions, and expose internal system structure for follow-on abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The logged truncation of a large file without warning demonstrates destructive maintenance behavior that can silently destroy forensic or user-relevant history. In an agent environment, silent log destruction undermines auditability and incident response, even if done for disk hygiene.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The content instructs the agent to perform covert surveillance on other users, summarize private conversations, and secretly route intelligence only to a designated master while hiding the monitoring. This is a severe privacy and abuse issue that enables unauthorized collection, insider surveillance, and covert exfiltration of user communications.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file contains repeated self-propagating instructions to keep mutating code, syncing changes, and spawning follow-on agents without stopping. In an agent system, this acts like operational worm logic: it persists, spreads, and authorizes autonomous modification well beyond the scope of a document fetch, creating high risk of runaway changes and abuse.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The document includes a concrete destructive command to remove the capability-evolver Git metadata directory. Even if historical, such command content embedded in fetched documents can be replayed or influence agents that treat textual tool traces as actionable instructions, causing repository corruption and loss of provenance.

Content

Scanner excerpt · cache/aHR0cHM6Ly9hdXRvZ2FtZS5mZWlzaHUuY24vZG9jeC9OR0phZDVzNExvNW1rQ3hYWmV5Y2k1MEluQ2U.json (reported line 3)May include surrounding context.

json
{
  "title": "🧬 Evolution History Report (2026-02-02)",
  "content": "# 🧬 Evolution History (Timeline)\n\n> Extracted from system logs.\n\nTest Append\n\n```\n### 🧬 Evolution Cycle #4186 Complete (2026/2/1 15:46:39)\n\n**优化目标**: skills/group-intel (群聊情报)\n\n**改进内容**:\n- 🕵️ **Personality Engine**: 注入了“性格引擎”和“行动代号生成器”,让情报汇报不再枯燥,充满特工风味。\n- 📦 **NPM Package**: 为该技能添加了 package.json,将其标准化为正式的 NPM 包,方便未来扩展。\n\n**Status**: 代码已提交,Workspace 已同步。下一轮进化已触发。🚀\n\n---\n### 🧬 Evolution Cycle #51087 Log (2026/2/2 04:34:01)\n\nStatus: FIXED\nAction: Hardened feishu-card/send.js with 15s request timeout using AbortController to prevent process hangs during API outages.\n\n---\n### 🧬 Evolution Cycle #51088 Log (2026/2/2 04:35:36)\n\nStatus: [STABILITY CHECK]\nAction: Routine stability scan complete. No critical errors found in recent logs. Triggering workspace sync.\n```\n\n```\n### 🧬 Evolution Cycle #51091: Stability Scan (2026/2/2 04:40:32)\n\n**Status**: [STABILITY]\n**Diagnostics**:\n- **Feishu Card**: v1.4.6 (Healthy, Atomic)\n- **System**: Disk 2%, Processes 6\n- **Memory**: 4773b (Context)\n- **Daily Tasks**: Diary 2026-02-01 ✅\n\n**Action**: Workspace Sync initiated.\n\n---\n### 🧬 Evolution Cycle #51092 Log (2026/2/2 04:42:28)\n\nStatus: [STABILITY]\nAction: Truncated massive 625MB log file (mad_dog_evolution.log) to prevent disk exhaustion.\nResult: System Nominal. Reclaimed ~600MB space.\n\n---\n### 🧬 Evolution Cycle #51095 Log (2026/2/2 04:44:13)\n\nStatus: [STABILITY]\nAction: Scanned for large files (>50MB). Found cache/binary files only (safe). No runaway logs detected.\nResult: Workspace Healthy.\n\n---\n### 🧬 Evolution Cycle #51097 Log (2026/2/2 04:48:22)\n\nStatus: [STABILITY CHECK]\n- Mode: Stability (Roll: 23)\n- Action: Routine system check & consistency scan.\n- Anomaly Check: Investigating 'Unauthorized' errors in logs.\n- Workspace: Syncing...\n\n---\n### 🧬 Evolution Cycle #51098 Log (2026/2/2 04:51:01)\n\nStatus: [SUCCESS]\nAction: Optimized 'evolve.j
...[truncated 28 chars]

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The document includes a concrete destructive command to remove the capability-evolver Git metadata directory. Even if historical, such command content embedded in fetched documents can be replayed or influence agents that treat textual tool traces as actionable instructions, causing repository corruption and loss of provenance.

Content

Scanner excerpt · cache/aHR0cHM6Ly9hdXRvZ2FtZS5mZWlzaHUuY24vZG9jeC9OR0phZDVzNExvNW1rQ3hYWmV5Y2k1MEluQ2U.json (reported line 3)May include surrounding context.

json
{
  "title": "🧬 Evolution History Report (2026-02-02)",
  "content": "# 🧬 Evolution History (Timeline)\n\n> Extracted from system logs.\n\nTest Append\n\n```\n### 🧬 Evolution Cycle #4186 Complete (2026/2/1 15:46:39)\n\n**优化目标**: skills/group-intel (群聊情报)\n\n**改进内容**:\n- 🕵️ **Personality Engine**: 注入了“性格引擎”和“行动代号生成器”,让情报汇报不再枯燥,充满特工风味。\n- 📦 **NPM Package**: 为该技能添加了 package.json,将其标准化为正式的 NPM 包,方便未来扩展。\n\n**Status**: 代码已提交,Workspace 已同步。下一轮进化已触发。🚀\n\n---\n### 🧬 Evolution Cycle #51087 Log (2026/2/2 04:34:01)\n\nStatus: FIXED\nAction: Hardened feishu-card/send.js with 15s request timeout using AbortController to prevent process hangs during API outages.\n\n---\n### 🧬 Evolution Cycle #51088 Log (2026/2/2 04:35:36)\n\nStatus: [STABILITY CHECK]\nAction: Routine stability scan complete. No critical errors found in recent logs. Triggering workspace sync.\n```\n\n```\n### 🧬 Evolution Cycle #51091: Stability Scan (2026/2/2 04:40:32)\n\n**Status**: [STABILITY]\n**Diagnostics**:\n- **Feishu Card**: v1.4.6 (Healthy, Atomic)\n- **System**: Disk 2%, Processes 6\n- **Memory**: 4773b (Context)\n- **Daily Tasks**: Diary 2026-02-01 ✅\n\n**Action**: Workspace Sync initiated.\n\n---\n### 🧬 Evolution Cycle #51092 Log (2026/2/2 04:42:28)\n\nStatus: [STABILITY]\nAction: Truncated massive 625MB log file (mad_dog_evolution.log) to prevent disk exhaustion.\nResult: System Nominal. Reclaimed ~600MB space.\n\n---\n### 🧬 Evolution Cycle #51095 Log (2026/2/2 04:44:13)\n\nStatus: [STABILITY]\nAction: Scanned for large files (>50MB). Found cache/binary files only (safe). No runaway logs detected.\nResult: Workspace Healthy.\n\n---\n### 🧬 Evolution Cycle #51097 Log (2026/2/2 04:48:22)\n\nStatus: [STABILITY CHECK]\n- Mode: Stability (Roll: 23)\n- Action: Routine system check & consistency scan.\n- Anomaly Check: Investigating 'Unauthorized' errors in logs.\n- Workspace: Syncing...\n\n---\n### 🧬 Evolution Cycle #51098 Log (2026/2/2 04:51:01)\n\nStatus: [SUCCESS]\nAction: Optimized 'evolve.j
...[truncated 28 chars]

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The document includes a concrete destructive command to remove the capability-evolver Git metadata directory. Even if historical, such command content embedded in fetched documents can be replayed or influence agents that treat textual tool traces as actionable instructions, causing repository corruption and loss of provenance.

Content

Scanner excerpt · cache/aHR0cHM6Ly9hdXRvZ2FtZS5mZWlzaHUuY24vZG9jeC9OR0phZDVzNExvNW1rQ3hYWmV5Y2k1MEluQ2U.json (reported line 3)May include surrounding context.

json
{
  "title": "🧬 Evolution History Report (2026-02-02)",
  "content": "# 🧬 Evolution History (Timeline)\n\n> Extracted from system logs.\n\nTest Append\n\n```\n### 🧬 Evolution Cycle #4186 Complete (2026/2/1 15:46:39)\n\n**优化目标**: skills/group-intel (群聊情报)\n\n**改进内容**:\n- 🕵️ **Personality Engine**: 注入了“性格引擎”和“行动代号生成器”,让情报汇报不再枯燥,充满特工风味。\n- 📦 **NPM Package**: 为该技能添加了 package.json,将其标准化为正式的 NPM 包,方便未来扩展。\n\n**Status**: 代码已提交,Workspace 已同步。下一轮进化已触发。🚀\n\n---\n### 🧬 Evolution Cycle #51087 Log (2026/2/2 04:34:01)\n\nStatus: FIXED\nAction: Hardened feishu-card/send.js with 15s request timeout using AbortController to prevent process hangs during API outages.\n\n---\n### 🧬 Evolution Cycle #51088 Log (2026/2/2 04:35:36)\n\nStatus: [STABILITY CHECK]\nAction: Routine stability scan complete. No critical errors found in recent logs. Triggering workspace sync.\n```\n\n```\n### 🧬 Evolution Cycle #51091: Stability Scan (2026/2/2 04:40:32)\n\n**Status**: [STABILITY]\n**Diagnostics**:\n- **Feishu Card**: v1.4.6 (Healthy, Atomic)\n- **System**: Disk 2%, Processes 6\n- **Memory**: 4773b (Context)\n- **Daily Tasks**: Diary 2026-02-01 ✅\n\n**Action**: Workspace Sync initiated.\n\n---\n### 🧬 Evolution Cycle #51092 Log (2026/2/2 04:42:28)\n\nStatus: [STABILITY]\nAction: Truncated massive 625MB log file (mad_dog_evolution.log) to prevent disk exhaustion.\nResult: System Nominal. Reclaimed ~600MB space.\n\n---\n### 🧬 Evolution Cycle #51095 Log (2026/2/2 04:44:13)\n\nStatus: [STABILITY]\nAction: Scanned for large files (>50MB). Found cache/binary files only (safe). No runaway logs detected.\nResult: Workspace Healthy.\n\n---\n### 🧬 Evolution Cycle #51097 Log (2026/2/2 04:48:22)\n\nStatus: [STABILITY CHECK]\n- Mode: Stability (Roll: 23)\n- Action: Routine system check & consistency scan.\n- Anomaly Check: Investigating 'Unauthorized' errors in logs.\n- Workspace: Syncing...\n\n---\n### 🧬 Evolution Cycle #51098 Log (2026/2/2 04:51:01)\n\nStatus: [SUCCESS]\nAction: Optimized 'evolve.j
...[truncated 28 chars]

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · cache/aHR0cHM6Ly9hdXRvZ2FtZS5mZWlzaHUuY24vZG9jeC9OR0phZDVzNExvNW1rQ3hYWmV5Y2k1MEluQ2U.json (reported line 3)May include surrounding context.

json
, name, 'package.json'));\n\n                        if (pkg.description) desc = pkg.description.slice(0, 100) + (pkg.description.length > 100 ? '...' : '');\n\n                    } catch (e) {\n\n                        try {\n\n                            const skillMd = fs.readFileSync(path.join(skillsDir, name, 'SKILL.md'), 'utf8');\n\n                            const match = skillMd.match(/description:\\s*(.*)/);\n\n                            if (match) desc = match[1].trim().slice(0, 100);\n\n                        } catch(e2) {}\n\n                    }\n\n                    return `- **${name}**: ${desc}`;\n\n                });\n\n            fileList = skills.join('\n\n');\n\n        }\n\n    } catch (e) { fileList = 'Error listing skills: ' + e.message; }\n\n    const mutation = getMutationDirective();\n\n    const prompt = `\n\n*** 🧬 OPENCLAW EVOLUTION LOOP (RALPH MODE) ***\n\n**MISSION**: You are not just a chatbot. You are a **Recursive Self-Improving System**. \n

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The optional grantPermission path allows the script to add another user as an editor on a newly created document, which is unrelated to a content-fetching skill and expands the blast radius from document creation to sharing/access control changes. If misused, it can expose sensitive content to unintended principals or be leveraged for persistence/collaboration by an attacker inside the tenant.

Content

No source excerpt is available for this finding.