T09 · Insecure Skill Coding Practices
- Location
schema.json:17- Finding
Access Tokens Are Accepted as Plaintext Agent Inputs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Feishu/DingTalk workflow helper, but it asks users to pass broad enterprise access tokens as ordinary inputs without enough scoping or secret-handling controls.
Review before installing in a real enterprise environment. Use only narrowly scoped, short-lived Feishu/DingTalk credentials, avoid pasting production tokens into chat or ordinary workflow fields, prefer a managed secret or OAuth connection if available, and confirm the host redacts tokens from logs and traces.
schema.json:17Access Tokens Are Accepted as Plaintext Agent Inputs
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
auth_token:
type: string
required: true
description: 平台应用访问凭证(App Token/Access Token)
query_context:
type: string
required: false
The schema explicitly requests an auth_token as a raw string input, which creates a credential-handling surface inside the skill interface. Passing bearer-style access tokens through skill parameters increases the risk of token exposure via logs, prompts, telemetry, error messages, or downstream misuse, especially because the skill bridges multiple enterprise platforms and may access calendars, approvals, documents, and tasks.
},
"auth_token": {
"type": "string",
"description": "平台应用访问凭证(App Access Token / Tenant Access Token)"
},
"query_context": {
"type": "string",
The README instructs users to obtain and pass high-privilege enterprise access tokens such as tenant_access_token and access_token, but does not warn about secure storage, least-privilege scoping, redaction in logs, or secret rotation. In an agent skill context, this is risky because users may paste live credentials into prompts, configs, or telemetry paths, leading to token leakage and unauthorized access to calendars, approvals, documents, or workflow data.
The manifest text is entirely in Chinese and does not offer any language choice or explain that the skill is intended only for a Chinese-speaking or region-specific environment. This creates a natural-language locale policy issue because the skill appears to impose a specific language without explicit user opt-in or justification.
The README presents the skill description and setup instructions entirely in Chinese, which can amount to a language policy issue when no user choice or locale justification is provided. There is no indication that the skill is intentionally restricted to a Chinese-speaking or China-specific audience.
No suspicious patterns detected.