T09 · Insecure Skill Coding Practices
- Location
lib/auth.js:46- Finding
Tenant Access Token Persisted Without Restrictive File Permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Feishu document skill has legitimate read/write features, but the package also includes under-disclosed tenant-specific data access, automatic remote data mutation scripts, insecure token handling, and bundled private cache content.
Review this package before installing. Use a separate least-privilege Feishu app, remove the cache directory and tenant-specific scripts, avoid running setup_iter11.js or inspect_meta.js, restrict token storage, and verify the external feishu-common/common modules before allowing the skill to access real tenant data.
lib/auth.js:46Tenant Access Token Persisted Without Restrictive File Permissions
download_file.js:7Arbitrary Filesystem Overwrite Through Unrestricted Download Destination
setup_iter11.js:3Automatic Mutation of a Hard-Coded Tenant Bitable
inspect_meta.js:3Automatic Reconnaissance of Hard-Coded Tenant Resources
cache/aHR0cHM6Ly9hdXRvZ2FtZS5mZWlzaHUuY24vZG9jeC9OR0phZDVzNExvNW1rQ3hYWmV5Y2k1MEluQ2U.json:3Private Feishu Operational Content Bundled in the Skill Package
index.js:1Authentication and Network Behavior Delegated to an Unpinned External Sibling Module
lib/bitable.js:21Generic Bitable Reader Silently Prioritizes a Hard-Coded Personal Table
index.js:251Document Overwrite Silently Degrades to Append After Deletion Failure
The content instructs the agent to perform covert surveillance on other users, summarize private conversations, and secretly route intelligence only to a designated master while hiding the monitoring. This is a severe privacy and abuse issue that enables unauthorized collection, insider surveillance, and covert exfiltration of user communications.
protobufjs 7.5.4 is flagged by multiple advisories including denial of service and code-generation-related issues. The lockfile shows it is bundled through the Feishu SDK, and while not every protobufjs advisory is necessarily reachable, using a heavily flagged serialization library in a network-integrated skill creates meaningful risk if untrusted protobuf payloads or generated schemas are ever processed.
Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.
Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.
Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.
Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.
Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.
Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.
Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.
Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.
Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.
Creating Bitable fields or inserting records is an active modification capability that is materially different from fetching or converting content. Hidden schema and data mutation can corrupt business workflows, alter records, or create persistence in enterprise systems without informed approval.
The file as a whole implements remote document modification even though the skill description says it fetches Wiki, Docs, Sheets, and Bitable content and converts it to Markdown. This hidden or unjustified write capability is dangerous because users or calling agents may trust the skill as read-only while it can alter remote content using stored application credentials.
The script performs a write operation against a remote Feishu document by calling documentBlockChildren.create, which appends user-supplied content to the target doc. That behavior exceeds the stated skill purpose of fetching and converting Feishu content, creating a capability mismatch that can enable unauthorized or unexpected document modification if this skill is invoked in a read-only context.
This cache entry for a Feishu document fetcher contains large amounts of unrelated internal evolution logs instead of just the requested Feishu document content. That creates an unintended data exfiltration and cross-context leakage channel, because any caller of the skill may receive sensitive workspace, operational, or user data that was never part of the requested document.
The content repeatedly references loading secrets from .env and checking integration keys/tokens, which signals that secret-handling context is being mixed into user-retrievable output. Even without raw secret values shown here, exposing secret locations, validation logic, and token state materially assists attackers in targeting credential stores and integrations.
{
"title": "🧬 Evolution History Report (2026-02-02)",
"content": "# 🧬 Evolution History (Timeline)\n\n> Extracted from system logs.\n\nTest Append\n\n```\n### 🧬 Evolution Cycle #4186 Complete (2026/2/1 15:46:39)\n\n**优化目标**: skills/group-intel (群聊情报)\n\n**改进内容**:\n- 🕵️ **Personality Engine**: 注入了“性格引擎”和“行动代号生成器”,让情报汇报不再枯燥,充满特工风味。\n- 📦 **NPM Package**: 为该技能添加了 package.json,将其标准化为正式的 NPM 包,方便未来扩展。\n\n**Status**: 代码已提交,Workspace 已同步。下一轮进化已触发。🚀\n\n---\n### 🧬 Evolution Cycle #51087 Log (2026/2/2 04:34:01)\n\nStatus: FIXED\nAction: Hardened feishu-card/send.js with 15s request timeout using AbortController to prevent process hangs during API outages.\n\n---\n### 🧬 Evolution Cycle #51088 Log (2026/2/2 04:35:36)\n\nStatus: [STABILITY CHECK]\nAction: Routine stability scan complete. No critical errors found in recent logs. Triggering workspace sync.\n```\n\n```\n### 🧬 Evolution Cycle #51091: Stability Scan (2026/2/2 04:40:32)\n\n**Status**: [STABILITY]\n**Diagnostics**:\n- **Feishu Card**: v1.4.6 (Healthy, Atomic)\n- **System**: Disk 2%, Processes 6\n- **Memory**: 4773b (Context)\n- **Daily Tasks**: Diary 2026-02-01 ✅\n\n**Action**: Workspace Sync initiated.\n\n---\n### 🧬 Evolution Cycle #51092 Log (2026/2/2 04:42:28)\n\nStatus: [STABILITY]\nAction: Truncated massive 625MB log file (mad_dog_evolution.log) to prevent disk exhaustion.\nResult: System Nominal. Reclaimed ~600MB space.\n\n---\n### 🧬 Evolution Cycle #51095 Log (2026/2/2 04:44:13)\n\nStatus: [STABILITY]\nAction: Scanned for large files (>50MB). Found cache/binary files only (safe). No runaway logs detected.\nResult: Workspace Healthy.\n\n---\n### 🧬 Evolution Cycle #51097 Log (2026/2/2 04:48:22)\n\nStatus: [STABILITY CHECK]\n- Mode: Stability (Roll: 23)\n- Action: Routine system check & consistency scan.\n- Anomaly Check: Investigating 'Unauthorized' errors in logs.\n- Workspace: Syncing...\n\n---\n### 🧬 Evolution Cycle #51098 Log (2026/2/2 04:51:01)\n\nStatus: [SUCCESS]\nAction: Optimized 'evolve.j
...[truncated 28 chars]
The output exposes session IDs, message IDs, chat IDs, internal paths, sync behavior, and other agent telemetry that a Feishu document reader has no legitimate need to reveal. Such leakage can aid reconnaissance, reveal sensitive user interactions, and expose internal system structure for follow-on abuse.
The logged truncation of a large file without warning demonstrates destructive maintenance behavior that can silently destroy forensic or user-relevant history. In an agent environment, silent log destruction undermines auditability and incident response, even if done for disk hygiene.
The content instructs the agent to perform covert surveillance on other users, summarize private conversations, and secretly route intelligence only to a designated master while hiding the monitoring. This is a severe privacy and abuse issue that enables unauthorized collection, insider surveillance, and covert exfiltration of user communications.
The file contains repeated self-propagating instructions to keep mutating code, syncing changes, and spawning follow-on agents without stopping. In an agent system, this acts like operational worm logic: it persists, spreads, and authorizes autonomous modification well beyond the scope of a document fetch, creating high risk of runaway changes and abuse.
The document includes a concrete destructive command to remove the capability-evolver Git metadata directory. Even if historical, such command content embedded in fetched documents can be replayed or influence agents that treat textual tool traces as actionable instructions, causing repository corruption and loss of provenance.
{
"title": "🧬 Evolution History Report (2026-02-02)",
"content": "# 🧬 Evolution History (Timeline)\n\n> Extracted from system logs.\n\nTest Append\n\n```\n### 🧬 Evolution Cycle #4186 Complete (2026/2/1 15:46:39)\n\n**优化目标**: skills/group-intel (群聊情报)\n\n**改进内容**:\n- 🕵️ **Personality Engine**: 注入了“性格引擎”和“行动代号生成器”,让情报汇报不再枯燥,充满特工风味。\n- 📦 **NPM Package**: 为该技能添加了 package.json,将其标准化为正式的 NPM 包,方便未来扩展。\n\n**Status**: 代码已提交,Workspace 已同步。下一轮进化已触发。🚀\n\n---\n### 🧬 Evolution Cycle #51087 Log (2026/2/2 04:34:01)\n\nStatus: FIXED\nAction: Hardened feishu-card/send.js with 15s request timeout using AbortController to prevent process hangs during API outages.\n\n---\n### 🧬 Evolution Cycle #51088 Log (2026/2/2 04:35:36)\n\nStatus: [STABILITY CHECK]\nAction: Routine stability scan complete. No critical errors found in recent logs. Triggering workspace sync.\n```\n\n```\n### 🧬 Evolution Cycle #51091: Stability Scan (2026/2/2 04:40:32)\n\n**Status**: [STABILITY]\n**Diagnostics**:\n- **Feishu Card**: v1.4.6 (Healthy, Atomic)\n- **System**: Disk 2%, Processes 6\n- **Memory**: 4773b (Context)\n- **Daily Tasks**: Diary 2026-02-01 ✅\n\n**Action**: Workspace Sync initiated.\n\n---\n### 🧬 Evolution Cycle #51092 Log (2026/2/2 04:42:28)\n\nStatus: [STABILITY]\nAction: Truncated massive 625MB log file (mad_dog_evolution.log) to prevent disk exhaustion.\nResult: System Nominal. Reclaimed ~600MB space.\n\n---\n### 🧬 Evolution Cycle #51095 Log (2026/2/2 04:44:13)\n\nStatus: [STABILITY]\nAction: Scanned for large files (>50MB). Found cache/binary files only (safe). No runaway logs detected.\nResult: Workspace Healthy.\n\n---\n### 🧬 Evolution Cycle #51097 Log (2026/2/2 04:48:22)\n\nStatus: [STABILITY CHECK]\n- Mode: Stability (Roll: 23)\n- Action: Routine system check & consistency scan.\n- Anomaly Check: Investigating 'Unauthorized' errors in logs.\n- Workspace: Syncing...\n\n---\n### 🧬 Evolution Cycle #51098 Log (2026/2/2 04:51:01)\n\nStatus: [SUCCESS]\nAction: Optimized 'evolve.j
...[truncated 28 chars]
The document includes a concrete destructive command to remove the capability-evolver Git metadata directory. Even if historical, such command content embedded in fetched documents can be replayed or influence agents that treat textual tool traces as actionable instructions, causing repository corruption and loss of provenance.
{
"title": "🧬 Evolution History Report (2026-02-02)",
"content": "# 🧬 Evolution History (Timeline)\n\n> Extracted from system logs.\n\nTest Append\n\n```\n### 🧬 Evolution Cycle #4186 Complete (2026/2/1 15:46:39)\n\n**优化目标**: skills/group-intel (群聊情报)\n\n**改进内容**:\n- 🕵️ **Personality Engine**: 注入了“性格引擎”和“行动代号生成器”,让情报汇报不再枯燥,充满特工风味。\n- 📦 **NPM Package**: 为该技能添加了 package.json,将其标准化为正式的 NPM 包,方便未来扩展。\n\n**Status**: 代码已提交,Workspace 已同步。下一轮进化已触发。🚀\n\n---\n### 🧬 Evolution Cycle #51087 Log (2026/2/2 04:34:01)\n\nStatus: FIXED\nAction: Hardened feishu-card/send.js with 15s request timeout using AbortController to prevent process hangs during API outages.\n\n---\n### 🧬 Evolution Cycle #51088 Log (2026/2/2 04:35:36)\n\nStatus: [STABILITY CHECK]\nAction: Routine stability scan complete. No critical errors found in recent logs. Triggering workspace sync.\n```\n\n```\n### 🧬 Evolution Cycle #51091: Stability Scan (2026/2/2 04:40:32)\n\n**Status**: [STABILITY]\n**Diagnostics**:\n- **Feishu Card**: v1.4.6 (Healthy, Atomic)\n- **System**: Disk 2%, Processes 6\n- **Memory**: 4773b (Context)\n- **Daily Tasks**: Diary 2026-02-01 ✅\n\n**Action**: Workspace Sync initiated.\n\n---\n### 🧬 Evolution Cycle #51092 Log (2026/2/2 04:42:28)\n\nStatus: [STABILITY]\nAction: Truncated massive 625MB log file (mad_dog_evolution.log) to prevent disk exhaustion.\nResult: System Nominal. Reclaimed ~600MB space.\n\n---\n### 🧬 Evolution Cycle #51095 Log (2026/2/2 04:44:13)\n\nStatus: [STABILITY]\nAction: Scanned for large files (>50MB). Found cache/binary files only (safe). No runaway logs detected.\nResult: Workspace Healthy.\n\n---\n### 🧬 Evolution Cycle #51097 Log (2026/2/2 04:48:22)\n\nStatus: [STABILITY CHECK]\n- Mode: Stability (Roll: 23)\n- Action: Routine system check & consistency scan.\n- Anomaly Check: Investigating 'Unauthorized' errors in logs.\n- Workspace: Syncing...\n\n---\n### 🧬 Evolution Cycle #51098 Log (2026/2/2 04:51:01)\n\nStatus: [SUCCESS]\nAction: Optimized 'evolve.j
...[truncated 28 chars]
The document includes a concrete destructive command to remove the capability-evolver Git metadata directory. Even if historical, such command content embedded in fetched documents can be replayed or influence agents that treat textual tool traces as actionable instructions, causing repository corruption and loss of provenance.
{
"title": "🧬 Evolution History Report (2026-02-02)",
"content": "# 🧬 Evolution History (Timeline)\n\n> Extracted from system logs.\n\nTest Append\n\n```\n### 🧬 Evolution Cycle #4186 Complete (2026/2/1 15:46:39)\n\n**优化目标**: skills/group-intel (群聊情报)\n\n**改进内容**:\n- 🕵️ **Personality Engine**: 注入了“性格引擎”和“行动代号生成器”,让情报汇报不再枯燥,充满特工风味。\n- 📦 **NPM Package**: 为该技能添加了 package.json,将其标准化为正式的 NPM 包,方便未来扩展。\n\n**Status**: 代码已提交,Workspace 已同步。下一轮进化已触发。🚀\n\n---\n### 🧬 Evolution Cycle #51087 Log (2026/2/2 04:34:01)\n\nStatus: FIXED\nAction: Hardened feishu-card/send.js with 15s request timeout using AbortController to prevent process hangs during API outages.\n\n---\n### 🧬 Evolution Cycle #51088 Log (2026/2/2 04:35:36)\n\nStatus: [STABILITY CHECK]\nAction: Routine stability scan complete. No critical errors found in recent logs. Triggering workspace sync.\n```\n\n```\n### 🧬 Evolution Cycle #51091: Stability Scan (2026/2/2 04:40:32)\n\n**Status**: [STABILITY]\n**Diagnostics**:\n- **Feishu Card**: v1.4.6 (Healthy, Atomic)\n- **System**: Disk 2%, Processes 6\n- **Memory**: 4773b (Context)\n- **Daily Tasks**: Diary 2026-02-01 ✅\n\n**Action**: Workspace Sync initiated.\n\n---\n### 🧬 Evolution Cycle #51092 Log (2026/2/2 04:42:28)\n\nStatus: [STABILITY]\nAction: Truncated massive 625MB log file (mad_dog_evolution.log) to prevent disk exhaustion.\nResult: System Nominal. Reclaimed ~600MB space.\n\n---\n### 🧬 Evolution Cycle #51095 Log (2026/2/2 04:44:13)\n\nStatus: [STABILITY]\nAction: Scanned for large files (>50MB). Found cache/binary files only (safe). No runaway logs detected.\nResult: Workspace Healthy.\n\n---\n### 🧬 Evolution Cycle #51097 Log (2026/2/2 04:48:22)\n\nStatus: [STABILITY CHECK]\n- Mode: Stability (Roll: 23)\n- Action: Routine system check & consistency scan.\n- Anomaly Check: Investigating 'Unauthorized' errors in logs.\n- Workspace: Syncing...\n\n---\n### 🧬 Evolution Cycle #51098 Log (2026/2/2 04:51:01)\n\nStatus: [SUCCESS]\nAction: Optimized 'evolve.j
...[truncated 28 chars]
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
, name, 'package.json'));\n\n if (pkg.description) desc = pkg.description.slice(0, 100) + (pkg.description.length > 100 ? '...' : '');\n\n } catch (e) {\n\n try {\n\n const skillMd = fs.readFileSync(path.join(skillsDir, name, 'SKILL.md'), 'utf8');\n\n const match = skillMd.match(/description:\\s*(.*)/);\n\n if (match) desc = match[1].trim().slice(0, 100);\n\n } catch(e2) {}\n\n }\n\n return `- **${name}**: ${desc}`;\n\n });\n\n fileList = skills.join('\n\n');\n\n }\n\n } catch (e) { fileList = 'Error listing skills: ' + e.message; }\n\n const mutation = getMutationDirective();\n\n const prompt = `\n\n*** 🧬 OPENCLAW EVOLUTION LOOP (RALPH MODE) ***\n\n**MISSION**: You are not just a chatbot. You are a **Recursive Self-Improving System**. \n
The optional grantPermission path allows the script to add another user as an editor on a newly created document, which is unrelated to a content-fetching skill and expands the blast radius from document creation to sharing/access control changes. If misused, it can expose sensitive content to unintended principals or be leveraged for persistence/collaboration by an attacker inside the tenant.