Back to skill

Security audit

Feishu Post

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but it also ships an undocumented debug script that can read and print Feishu messages using the configured credentials.

Review before installing. The core sender is coherent, but remove or quarantine debug_msg.js unless you intentionally want a diagnostic that reads Feishu messages, and grant the Feishu app only the permissions needed to send posts. Treat message text as sensitive on shared machines because --text can be written briefly to /tmp, avoid sending untrusted Markdown links without validation, and refresh the npm dependencies before production use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
debug_msg.js:3
Finding

Undocumented Authenticated Retrieval and Logging of Feishu Messages

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
send.js:174
Finding

Plaintext Message Content Written to an Insecure Temporary File

Content
View full analysis
{ try { fs.unlinkSync(tmpPath); } catch (_) {} }).catch((e) => { try { fs.unlinkSync(tmpPath); } catch (_) {} process.exit(1); }); } ``` ### Technical Analysis Message text supplied through `--text` is unnecessarily copied into a plaintext file under the shared `/tmp` directory. The file is created with the process's default mode and is therefore dependent on the runtime umask. In environments with a common umask of `022`, the resulting file may be readable by other local users. The filename combines a timestamp with `Math.random()`, which is not a cryptographically secure random generator. File creation also does not use exclusive mode, such as `wx`, and does not explicitly reject a pre-existing path. Cleanup only occurs when the returned promise resolves or rejects normally; abrupt process termination can leave the file behind. ### Attack Path 1. A user supplies confidential Feishu content through the `--text` option. 2. The CLI writes the complete plaintext message into a file under `/tmp`. 3. Before deletion, another local process may discover and read the file if filesystem permissions allow it. 4. If the process terminates unexpectedly, the temporary file may remain after the Skill exits. 5. In an environment where an attacker can predict or discover the path before creation, the lack of exclusive creation also increases exposure ...[truncated 530 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
utils/markdown-parser.js:44
Finding

Unrestricted URI Schemes in Generated Feishu Links

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (14)

Known Vulnerable Dependency: protobufjs==7.5.4 — 12 advisory(ies): CVE-2026-44294 (protobuf.js: Denial of service from crafted field names in generated code); CVE-2026-44293 (protobuf.js: Code injection through bytes field defaults in generated toObject c); CVE-2026-44289 (protobuf.js: Denial of service through unbounded protobuf recursion) +9 more

Critical
Category
Supply Chain
Confidence
96% confidence
Finding

protobufjs 7.5.4 is installed with multiple serious advisories including denial of service, recursion issues, and potential code-injection paths in generated-code workflows. Even if only some code paths are used, this is a high-risk transitive dependency because protobuf parsing often processes structured external data and failures can lead to crashes or unsafe code generation behaviors.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.4 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
97% confidence
Finding

axios 1.13.4 is directly present and the advisories include SSRF, credential leakage, redirect handling, and prototype-pollution-related MITM impacts. Because this skill appears to post to external Feishu/Lark APIs, HTTP client behavior is security-relevant, making these issues materially more dangerous than in an offline-only tool.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
92% confidence
Finding

form-data 4.0.5 is present and the CRLF injection issue is a real vulnerability when multipart field names or filenames can be influenced by an attacker. If this skill ever uploads files or constructs multipart requests from untrusted input, malformed parts could smuggle headers or corrupt downstream request parsing.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
93% confidence
Finding

ws 8.19.0 is present and the advisories cover memory disclosure and memory exhaustion from crafted WebSocket traffic. If the Lark/Feishu SDK uses WebSockets for eventing or messaging, a network-reachable attacker could potentially trigger information leakage or denial of service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script logs full Feishu message API responses, including the current message and its parent, directly to the console. Message payloads can contain sensitive business content, metadata, user identifiers, or tokens-in-content, and console/log sinks are often retained, aggregated, or exposed to operators beyond the intended audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The payload is always constructed under the zh_cn locale key, which forces a specific language/locale behavior for all uses of the skill. There is no option for the user to choose another locale and no comment indicating that the skill is intentionally limited to a China-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The payload is always constructed under the zh_cn locale key, which forces a specific language/locale behavior for all users. This is a natural-language policy concern because the file provides no opt-in, alternative locale selection, or justification that the skill is intended only for a Chinese-language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This JavaScript mapping is built around Chinese bracketed labels such as "[亲亲]" and "[我想静静]", but the file provides no natural-language indication that the skill is intentionally Chinese-locale-specific or that users can opt into that locale. Per the policy, forcing a specific language without user choice or documented justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @protobufjs/utf8==1.1.0 — 1 advisory(ies): CVE-2026-44288 (protobufjs has overlong UTF-8 decoding)

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The lockfile pins @protobufjs/utf8 to 1.1.0, and the reported overlong UTF-8 decoding issue is a real supply-chain risk if this parser is ever used on attacker-controlled protobuf or text data. In this file it is only an indirect dependency, so exploitability depends on runtime code paths, but the vulnerable package is genuinely present.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: follow-redirects==1.15.11 — 1 advisory(ies): CVE-2026-40895 (follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Ta)

Low
Category
Supply Chain
Confidence
89% confidence
Finding

follow-redirects 1.15.11 is present and the cited issue can leak authentication headers across cross-domain redirects. Since axios depends on this package, any requests made with sensitive headers could expose secrets if redirect behavior is triggered to attacker-controlled domains.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: qs==6.14.1 — 3 advisory(ies): CVE-2026-82417 (qs: Denial of Service via Attacker Controlled isBuffer); CVE-2026-8723 (qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/u); CVE-2026-2391 (qs's arrayLimit bypass in comma parsing allows denial of service)

Low
Category
Supply Chain
Confidence
90% confidence
Finding

qs 6.14.1 is present and the cited issues are denial-of-service conditions triggered by crafted inputs during query-string parsing/stringification. This is a genuine dependency risk, though impact is lower unless the skill parses attacker-controlled query structures at scale or exposes an HTTP-facing service.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 7)May include surrounding context.

json
"description": "Send rich text messages (Post/RichText) to Feishu users/groups. Supports markdown conversion.",
  "main": "send.js",
  "dependencies": {
    "@larksuiteoapi/node-sdk": "^1.58.0",
    "commander": "^14.0.3",
    "dotenv": "^17.2.3"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"main": "send.js",
  "dependencies": {
    "@larksuiteoapi/node-sdk": "^1.58.0",
    "commander": "^14.0.3",
    "dotenv": "^17.2.3"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 9)May include surrounding context.

json
"dependencies": {
    "@larksuiteoapi/node-sdk": "^1.58.0",
    "commander": "^14.0.3",
    "dotenv": "^17.2.3"
  }
}