Back to skill

Security audit

feishu-sticker

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but it can silently choose a Feishu recipient from shared local state and stores an access token in a plaintext shared cache.

Review this before installing. Use an explicit --target every time, avoid sensitive images, restrict the Feishu app permissions, and protect or disable the local token cache. The skill is not clearly malicious, but its recipient auto-detection and plaintext token persistence make it suitable for Review rather than automatic approval.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
send.js:25
Finding

Feishu Tenant Access Token Stored in an Unprotected Plaintext File

Content
View full analysis
now + 60) { return cached.token; } } catch (e) {} } if (forceRefresh) { try { if (fs.existsSync(TOKEN_CACHE_FILE)) fs.unlinkSync(TOKEN_CACHE_FILE); } catch(e) {} } try { const res = await fetch('https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal', { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ app_id: APP_ID, app_secret: APP_SECRET }) }); const data = await res.json(); if (data.code !== 0) throw new Error(`API Error: ${data.msg}`); // 2. Update Memory Cache (File) try { const cacheData = { token: data.tenant_access_token, expire: now + data.expire }; const cacheDir = path.dirname(TOKEN_CACHE_FILE); if (!fs.existsSync(cacheDir)) fs.mkdirSync(cacheDir, { recursive: true }); fs.writeFileSync(TOKEN_CACHE_FILE, JSON.stringify(cacheData, null, 2)); } catch (e) { console.error("Failed to write token cache:", e.message); } return data.tenant_access_token; ``` ### Technical Analysis The Skill legitimately submits `FEISHU_APP_ID` and `FEISHU_APP_SECRET` to Feishu's official tenant-token endpoint because authentication is required to ...[truncated 1934 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
send.js:357
Finding

Undocumented Shared-Memory Inspection Enables Implicit and Potentially Unintended Recipient Selection

Content
View full analysis
0) return events[events.length - 1].user_id; } } catch (e) {} // 4. Default to Master return process.env.OPENCLAW_MASTER_ID || ''; } ``` The selected value is later used without recipient confirmation: ```js if (!opts.target) { opts.target = getAutoTarget(); console.log(`Auto-detected target: ${opts.target}`); } ``` ### Technical Analysis The documented usage supplies an explicit `--target`, but the implementation silently reads shared Agent state when that argument is absent. It examines `context.json` and `menu_events.json`, exposing session and interaction metadata to the Skill even though this access is not declared in `SKILL.md`. The selected value is not tied to the current invocation, freshness-checked, allowlisted, or confirmed by the user. A stale, unr ...[truncated 1423 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
send.js:177
Finding

String-Prefix Directory Check Can Delete GIF Files Outside the Sticker Directory

Content
View full analysis
WebP Conversion if (selectedFile.toLowerCase().endsWith('.gif') && ffmpegPath) { console.log('Detected GIF. Converting to WebP (Efficiency Protocol)...'); const webpPath = selectedFile.replace(/\.gif$/i, '.webp'); try { const ffmpegArgs = [ '-i', selectedFile, '-c:v', 'libwebp', '-lossless', '0', '-q:v', '75', '-loop', '0', '-an', '-vsync', '0', '-vf', 'scale=\'min(320,iw)\':-2', '-y', webpPath ]; spawnSync(ffmpegPath, ffmpegArgs, { stdio: 'pipe' }); if (fs.existsSync(webpPath)) { // SAFETY CHECK: Only delete if it's in our internal sticker stash const isInStickerDir = path.resolve(selectedFile).startsWith(stickerDir); if (isInStickerDir) { try { fs.unlinkSync(selectedFile); console.log('Original GIF deleted (Internal Storage Cleanup).'); } catch (delErr) { console.warn('Could not delete original GIF:', delErr.message); } } else { console.log('External file detected. Preserving original GIF.'); } selectedFile = webpPath; } ``` ### Technical Analysis The code attempts to protect externally supplied GIFs by deleting an original file only when its resolved path begins with `stickerDir`. A raw string-prefix comparison is not a valid directory-containment check. For example, if the intended directory is: ```text /home/user/.openclaw/media/stickers ``` then this external path also passes `startsWith(stickerDir)`: ```text /home/user/.openclaw/media/stickers-backup/example.g ...[truncated 1365 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill actually auto-detects recipients, reads shared local context/history, uses environment credentials, and transmits local images to Feishu while the manifest only describes sticker sending, users may unknowingly expose local data or send messages to unintended parties. Hidden recipient inference and undeclared credential/network behavior materially increase the risk of privacy leakage and unauthorized outbound communication.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the skill actually auto-detects recipients, reads shared local context/history, uses environment credentials, and transmits local images to Feishu while the manifest only describes sticker sending, users may unknowingly expose local data or send messages to unintended parties. Hidden recipient inference and undeclared credential/network behavior materially increase the risk of privacy leakage and unauthorized outbound communication.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · send.js (reported line 20)May include surrounding context.

js
}
}

require('dotenv').config({ path: require('path').resolve(__dirname, '../../.env') });

// Credentials
const APP_ID = process.env.FEISHU_APP_ID;

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill advertises capabilities that require network access and environment-variable use, but the manifest does not declare any tool scope or permissions boundaries. In agent ecosystems, missing explicit scope reduces transparency and can allow reviewers or users to invoke a skill without realizing it can access credentials and send data over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to provide local image files but does not warn that those files will be uploaded to Feishu's CDN. This omission can cause users to transmit sensitive or private local media off-device without informed consent, especially in environments where local sticker folders may contain personal or internal images.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The code accesses FEISHU_APP_ID and FEISHU_APP_SECRET from environment variables and uses them in an authentication request to the Feishu API. While failures are logged, there is no user-facing warning, comment, or prompt disclosing that credentials are read from the environment and sent to an external service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · send.js (reported line 50)May include surrounding context.

js
}

    try {
        const res = await fetch('https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal', {
            method: 'POST',
            headers: { 'Content-Type': 'application/json' },
            body: JSON.stringify({ app_id: APP_ID, app_secret: APP_SECRET })

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · send.js (reported line 112)May include surrounding context.

js
formData.append('image_type', 'message');
            formData.append('image', blob, path.basename(filePath));

            const res = await fetch('https://open.feishu.cn/open-apis/im/v1/images', {
                method: 'POST',
                headers: { 'Authorization': `Bearer ${token}` }, // Content-Type is auto-set by fetch
                body: formData

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill reads shared context and menu event files to infer a recipient, which expands behavior beyond simply sending a chosen sticker. In a messaging context, silently reusing prior session data can cause stickers to be sent to unintended users or chats, creating privacy and misdelivery risk without explicit user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill auto-detects a target and proceeds to send without a user-facing confirmation. In a chat-integrated tool, that can lead to unintended outbound messages to the wrong person or chat, especially because the recipient may come from shared state files rather than direct user input.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 22)May include surrounding context.

json
"author": "OpenClaw Agent",
  "license": "ISC",
  "dependencies": {
    "commander": "^13.1.0",
    "dotenv": "^16.4.7",
    "ffmpeg-static": "^5.2.0"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 23)May include surrounding context.

json
"license": "ISC",
  "dependencies": {
    "commander": "^13.1.0",
    "dotenv": "^16.4.7",
    "ffmpeg-static": "^5.2.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 24)May include surrounding context.

json
"dependencies": {
    "commander": "^13.1.0",
    "dotenv": "^16.4.7",
    "ffmpeg-static": "^5.2.0"
  }
}

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest says the skill sends images as Feishu stickers and mentions upload, caching, and GIF-to-WebP conversion. This function adds semantic sticker search/filtering by query and emotion via another module, which is extra functionality not disclosed in the stated purpose.

Content

No source excerpt is available for this finding.