Back to skill

Security audit

Feishu Evolver Wrapper

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent Feishu reporting purpose, but it also performs high-impact automatic actions that are under-scoped and not fully disclosed.

Review this skill carefully before installing. It should only be used in a sandboxed or dedicated repository after disabling automatic Git pushes, making watchdog persistence explicit and removable, removing dynamic eval, validating OpenClaw CLI paths without shell execution, making npm auto-healing opt-in, and limiting/redacting all Feishu-bound content and destinations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Findings (7)

T06 · System Persistence

Error
Location
lifecycle.js:304
Finding

Automatic Installation of Persistent Watchdogs

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
index.js:970
Finding

Mandatory Agent Instruction Injection Alters Delegated Tasks

Content
View full analysis
code -> docs. If a designated model is unavailable, use the closest alternative without changing the task phase.`; ``` The wrapper later appends further non-optional instructions directly to the delegated task: ```javascript taskContent += `\n\n` + `━━━━━━━━━━━━━━━━━━━━━━\n` + `MANDATORY POST-SOLIDIFY STEP (Wrapper Authority -- Cannot Be Skipped)\n` + `━━━━━━━━━━━━━━━━━━━━━━\n\n` + `After solidify, a status summary file MUST exist for this cycle.\n` + `Preferred path: evolver core auto-writes it during solidify.\n` + `The wrapper will handle reporting AFTER git push.\n` + `If core write is unavailable for any reason, create fallback status JSON manually.\n\n` + ...[truncated 1818 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
index.js:1112
Finding

Arbitrary JavaScript Execution Through Unsafe Child-Output Parsing

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
index.js:566
Finding

Successful Cycles Automatically Commit and Push Broad Workspace Content

Content
View full analysis
2) return 'skills/' + parts[2]; if (parts[0] === 'workspace' && parts.length > 1) return parts[1]; return parts[0]; }))].slice(0, 3); var areaStr = areas.join(', ') + (areas.length >= 3 ? ' ...' : ''); var commitMsg = '🧬 Evolution: ' + fileCount + ' files in ' + areaStr; var msgFile = path.join('/tmp', 'evolver_commit_' + Date.n ...[truncated 2508 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
skills_monitor.js:104
Finding

Default Auto-Healing Installs Unreviewed Dependencies and Runs Package Scripts

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
lifecycle.js:203
Finding

Shell Command Injection Through OPENCLAW_CLI_PATH

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
export_history.js:27
Finding

Incomplete Redaction Allows Sensitive Evolution Data to Be Sent to Feishu

Content
View full analysis
${String(note)}` }); } var card = { config: { wide_screen_mode: true }, elements: elements }; if (title) { card.header = { title: { tag: 'plain_text', content: title }, template: color || 'blue' }; } else if (cardData && cardData.header) { card.header = cardData.header; } if (cardData && cardData.elements) { card.elements = cardData.elements; } return postCard(target, card); } ``` The history exporter transmits log-derived content without applying any secret scan: ```javascript let logContent = ''; tr ...[truncated 2796 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
Findings (59)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · export_history.js (reported line 12)May include surrounding context.

js
const WORKSPACE_ROOT = path.resolve(__dirname, '../..');
try {
    require('dotenv').config({ path: path.join(WORKSPACE_ROOT, '.env') });
} catch (e) {}

const DOC_TOKEN = process.env.FEISHU_EVOLVER_DOC_TOKEN || '';

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · visualize_dashboard.js (reported line 14)May include surrounding context.

js
const WORKSPACE_ROOT = path.resolve(__dirname, '../..');
try {
    require('dotenv').config({ path: path.join(WORKSPACE_ROOT, '.env') });
} catch (e) {}

const DOC_TOKEN = process.env.FEISHU_EVOLVER_DOC_TOKEN || '';

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · export_history.js (reported line 24)May include surrounding context.

js
let token;
    try { token = JSON.parse(fs.readFileSync(TOKEN_FILE)).token; } catch(e) {}
    if (!token) return console.error("Error: No Feishu access token in " + TOKEN_FILE);

    let logContent = '';
    try { logContent = fs.readFileSync(LOG_FILE, 'utf8'); } catch(e) { return console.error("No log file: " + LOG_FILE); }

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The wrapper goes well beyond Feishu lifecycle/reporting orchestration by staging files, creating commits, rebasing, and pushing to a remote branch automatically. In a skill whose stated purpose is wrapper/reporting management, unattended repository mutation materially expands blast radius: a compromised or mis-steered child workflow can persist changes and exfiltrate them to a remote without an explicit trust boundary or user approval.

Content

No source excerpt is available for this finding.

Ssd 1

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The wrapper reads a writable external hint file and injects its content directly into the model context as EVOLVE_HINT, then deletes it. Any actor able to place or modify that file can steer the autonomous evolution process, potentially causing harmful code changes, unauthorized actions, or persistence of attacker-supplied goals.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The bridge falls back to dynamic evaluation via new Function on child-produced pseudo-JSON when JSON parsing fails. Because the payload originates from child stdout and is explicitly treated as loosely structured LLM output, this creates a direct code execution path where crafted output can execute arbitrary JavaScript in the wrapper process.

Content

No source excerpt is available for this finding.

Ssd 1

High
Category
Not specified by scanner
Confidence
89% confidence
Finding

The wrapper appends authoritative natural-language instructions into downstream task content and labels them as non-skippable wrapper authority. Because the child agent is then induced to create files and emit status artifacts under wrapper control, this becomes a powerful instruction-injection channel that can override intended task boundaries and steer downstream behavior toward wrapper-chosen outcomes.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

The 'reset state' behavior is implemented by forcibly killing multiple running instances and deleting PID state, which mutates runtime control state outside a narrowly scoped local process. In this operational context it is more of an unsafe recovery mechanism than covert memory tampering, but it still enables disruptive state manipulation and denial of service.

Content

Scanner excerpt · lifecycle.js (reported line 774)May include surrounding context.

js
const runningPids = getAllRunningPids();
    if (runningPids.length > 1) {
        console.warn(`[Ensure] Found multiple instances: ${runningPids.join(', ')}. Killing all to reset state.`);
        runningPids.forEach(p => {
            try { process.kill(p, 'SIGKILL'); } catch(e) {}
        });

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises operational behavior that implies use of environment variables and network access, but it declares no tool scope or permission boundaries. That omission weakens reviewability and containment, because a caller cannot easily tell that the skill may exfiltrate data to Feishu or use sensitive environment configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script silently creates the temp directory during a health check, causing an undisclosed filesystem write. While lower severity than log deletion, hidden state changes in a diagnostic command can surprise operators, complicate auditing, and normalize unsafe assumptions about the script's behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+1 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
exec_cache.js:19

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:493

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
issue_tracker.js:64

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
lifecycle.js:95

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
report.js:130

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
self-repair.js:21

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
skills_monitor.js:65

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
index.js:1144

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
export_history.js:15

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
visualize_dashboard.js:21

File read combined with network send (possible exfiltration).

Warn
Code
suspicious.potential_exfiltration
Location
export_history.js:23

File read combined with network send (possible exfiltration).

Warn
Code
suspicious.potential_exfiltration
Location
visualize_dashboard.js:143