T05 · Unauthorized Access and Privilege Escalation
- Location
debug_msg.js:3- Finding
Undocumented Authenticated Retrieval and Logging of Feishu Messages
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly does what it says, but it also ships an undocumented debug script that can read and print Feishu messages using the configured credentials.
Review before installing. The core sender is coherent, but remove or quarantine debug_msg.js unless you intentionally want a diagnostic that reads Feishu messages, and grant the Feishu app only the permissions needed to send posts. Treat message text as sensitive on shared machines because --text can be written briefly to /tmp, avoid sending untrusted Markdown links without validation, and refresh the npm dependencies before production use.
debug_msg.js:3Undocumented Authenticated Retrieval and Logging of Feishu Messages
send.js:174Plaintext Message Content Written to an Insecure Temporary File
utils/markdown-parser.js:44Unrestricted URI Schemes in Generated Feishu Links
protobufjs 7.5.4 is installed with multiple serious advisories including denial of service, recursion issues, and potential code-injection paths in generated-code workflows. Even if only some code paths are used, this is a high-risk transitive dependency because protobuf parsing often processes structured external data and failures can lead to crashes or unsafe code generation behaviors.
axios 1.13.4 is directly present and the advisories include SSRF, credential leakage, redirect handling, and prototype-pollution-related MITM impacts. Because this skill appears to post to external Feishu/Lark APIs, HTTP client behavior is security-relevant, making these issues materially more dangerous than in an offline-only tool.
form-data 4.0.5 is present and the CRLF injection issue is a real vulnerability when multipart field names or filenames can be influenced by an attacker. If this skill ever uploads files or constructs multipart requests from untrusted input, malformed parts could smuggle headers or corrupt downstream request parsing.
ws 8.19.0 is present and the advisories cover memory disclosure and memory exhaustion from crafted WebSocket traffic. If the Lark/Feishu SDK uses WebSockets for eventing or messaging, a network-reachable attacker could potentially trigger information leakage or denial of service.
The script logs full Feishu message API responses, including the current message and its parent, directly to the console. Message payloads can contain sensitive business content, metadata, user identifiers, or tokens-in-content, and console/log sinks are often retained, aggregated, or exposed to operators beyond the intended audience.
The payload is always constructed under the zh_cn locale key, which forces a specific language/locale behavior for all uses of the skill. There is no option for the user to choose another locale and no comment indicating that the skill is intentionally limited to a China-specific use case.
The payload is always constructed under the zh_cn locale key, which forces a specific language/locale behavior for all users. This is a natural-language policy concern because the file provides no opt-in, alternative locale selection, or justification that the skill is intended only for a Chinese-language context.
This JavaScript mapping is built around Chinese bracketed labels such as "[亲亲]" and "[我想静静]", but the file provides no natural-language indication that the skill is intentionally Chinese-locale-specific or that users can opt into that locale. Per the policy, forcing a specific language without user choice or documented justification can be a natural-language policy violation.
The lockfile pins @protobufjs/utf8 to 1.1.0, and the reported overlong UTF-8 decoding issue is a real supply-chain risk if this parser is ever used on attacker-controlled protobuf or text data. In this file it is only an indirect dependency, so exploitability depends on runtime code paths, but the vulnerable package is genuinely present.
follow-redirects 1.15.11 is present and the cited issue can leak authentication headers across cross-domain redirects. Since axios depends on this package, any requests made with sensitive headers could expose secrets if redirect behavior is triggered to attacker-controlled domains.
qs 6.14.1 is present and the cited issues are denial-of-service conditions triggered by crafted inputs during query-string parsing/stringification. This is a genuine dependency risk, though impact is lower unless the skill parses attacker-controlled query structures at scale or exposes an HTTP-facing service.
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"description": "Send rich text messages (Post/RichText) to Feishu users/groups. Supports markdown conversion.",
"main": "send.js",
"dependencies": {
"@larksuiteoapi/node-sdk": "^1.58.0",
"commander": "^14.0.3",
"dotenv": "^17.2.3"
}
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"main": "send.js",
"dependencies": {
"@larksuiteoapi/node-sdk": "^1.58.0",
"commander": "^14.0.3",
"dotenv": "^17.2.3"
}
}
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"dependencies": {
"@larksuiteoapi/node-sdk": "^1.58.0",
"commander": "^14.0.3",
"dotenv": "^17.2.3"
}
}