T09 · Insecure Skill Coding Practices
- Location
toggle_busy.js:10- Finding
Unvalidated Chat Identifier Enables Authenticated Feishu API URL Manipulation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Feishu group-management skill is purpose-aligned but should be reviewed because it can change shared chat names and permissions using authenticated Feishu API calls without strong scoping or input validation.
Install only if you trust the publisher and intend the agent to modify Feishu group settings. Use least-privileged Feishu credentials, restrict use to approved chat IDs, and require explicit user confirmation before changing names, descriptions, or permissions.
toggle_busy.js:10Unvalidated Chat Identifier Enables Authenticated Feishu API URL Manipulation
The skill enables changing shared Feishu group metadata and permissions, including who can edit group info, invite users, and use @All, but provides no requirement for explicit user confirmation or warning that these are side-effecting changes to a shared space. In an agent setting, this can lead to unintended administrative changes, social disruption, or reduced group integrity if the tool is invoked from ambiguous or insufficiently authorized requests.
The dependency uses a caret range (^14.0.3), which permits automatic installation of newer compatible versions rather than an exact vetted release. This creates supply-chain risk because a compromised or breaking upstream publish could be pulled into future installs without explicit review.
"description": "Manage Feishu group chats (settings, names, permissions).",
"main": "toggle_busy.js",
"dependencies": {
"commander": "^14.0.3",
"dotenv": "^17.2.3"
}
}
The dependency uses a caret range (^17.2.3), allowing npm to resolve to later patch/minor releases instead of a single audited version. In a skill that likely handles Feishu group-management credentials or environment-based secrets, unexpected dependency updates modestly increase the risk of supply-chain compromise.
"main": "toggle_busy.js",
"dependencies": {
"commander": "^14.0.3",
"dotenv": "^17.2.3"
}
}