Back to skill

Security audit

feishu-group-manager

Security checks for vulnerabilities and agentic risk

Overview

This Feishu group-management skill is purpose-aligned but should be reviewed because it can change shared chat names and permissions using authenticated Feishu API calls without strong scoping or input validation.

Install only if you trust the publisher and intend the agent to modify Feishu group settings. Use least-privileged Feishu credentials, restrict use to approved chat IDs, and require explicit user confirmation before changing names, descriptions, or permissions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
toggle_busy.js:10
Finding

Unvalidated Chat Identifier Enables Authenticated Feishu API URL Manipulation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables changing shared Feishu group metadata and permissions, including who can edit group info, invite users, and use @All, but provides no requirement for explicit user confirmation or warning that these are side-effecting changes to a shared space. In an agent setting, this can lead to unintended administrative changes, social disruption, or reduced group integrity if the tool is invoked from ambiguous or insufficiently authorized requests.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency uses a caret range (^14.0.3), which permits automatic installation of newer compatible versions rather than an exact vetted release. This creates supply-chain risk because a compromised or breaking upstream publish could be pulled into future installs without explicit review.

Content

Scanner excerpt · package.json (reported line 7)May include surrounding context.

json
"description": "Manage Feishu group chats (settings, names, permissions).",
  "main": "toggle_busy.js",
  "dependencies": {
    "commander": "^14.0.3",
    "dotenv": "^17.2.3"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency uses a caret range (^17.2.3), allowing npm to resolve to later patch/minor releases instead of a single audited version. In a skill that likely handles Feishu group-management credentials or environment-based secrets, unexpected dependency updates modestly increase the risk of supply-chain compromise.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"main": "toggle_busy.js",
  "dependencies": {
    "commander": "^14.0.3",
    "dotenv": "^17.2.3"
  }
}