T09 · Insecure Skill Coding Practices
- Location
index.js:54- Finding
Feishu Tenant Access Token Stored in Plaintext Without Restrictive Permissions
- Content
View full analysis
Vulnerability Details
File Location:
index.js, lines 54–56
Vulnerability Type: Plaintext storage of sensitive authentication data
Risk Level: Mediumjs const tokenData = { token: data.tenant_access_token, expire: Math.floor(Date.now() / 1000) + data.expire - 60 }; fs.writeFileSync(TOKEN_PATH, JSON.stringify(tokenData)); return tokenData.token;Technical Analysis
The Skill stores the Feishu tenant access token in
memory/feishu_token.jsonas plaintext. Thefs.writeFileSynccall does not specify a restrictive file mode, so the resulting permissions depend on the process umask or the permissions of an existing file.The token is also placed in the agent's memory directory. This increases its potential exposure to local users, other processes running under accessible accounts, backup or synchronization systems, and tooling that indexes or processes agent memory.
Caching the token is not strictly required for the declared search and digest functionality; it is a performance optimization. Although the token expires, anyone who obtains it before expiration may replay it against Feishu APIs. The token's effective privileges are those granted to the Feishu application.
The related network behavior is otherwise consistent with the declared functionality: the application credentials are sent only to the official Feishu authentication endpoint, and the bearer token is sent only to official Feishu API endpoints. No transmission of credentials or message data to an unrelated destination was identified.
Attack Path
- A user invokes
recall,search, ordigest. - The Skill sends the configured application ID and secret to Feishu's official authentication endpoint and receives a tenant access token.
- The Skill writes that token in plaintext to
memory/feishu_token.json. - A local user, process, backup system, synchronization service, or memory-indexing component with acces ...[truncated 852 chars]
- A user invokes
- Remediation
View remediation
Remediation Suggestions
- Prefer keeping tenant access tokens in memory and requesting a new token after process restart rather than persisting them.
- If persistent caching is necessary, store the cache outside the agent memory directory in a dedicated credential or runtime-state directory.
- Create the containing directory with mode
0700and write the token file with mode0600. - Use an atomic write procedure: create a new file with exclusive and restrictive permissions, write the data, flush it, and rename it into place.
- Before reading an existing cache, verify that it is a regular file, is owned by the expected user, and is not accessible by group or other users.
- Delete expired token files rather than leaving stale credentials on disk.
- Avoid including the credential cache in backups, synchronization, source control, logs, or memory-indexing pipelines.
- Run the Skill under a dedicated least-privileged operating-system account.
- Restrict the Feishu application to only the API scopes and chat access required for message retrieval.
- Consider using an operating-system credential store or managed secret-storage service if durable token storage is unavoidable.
