Back to skill

Security audit

feishu-dingtalk-bridge

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Feishu/DingTalk workflow helper, but it asks users to pass broad enterprise access tokens as ordinary inputs without enough scoping or secret-handling controls.

Review before installing in a real enterprise environment. Use only narrowly scoped, short-lived Feishu/DingTalk credentials, avoid pasting production tokens into chat or ordinary workflow fields, prefer a managed secret or OAuth connection if available, and confirm the host redacts tokens from logs and traces.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
schema.json:17
Finding

Access Tokens Are Accepted as Plaintext Agent Inputs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
auth_token:
    type: string
    required: true
    description: 平台应用访问凭证(App Token/Access Token)
  query_context:
    type: string
    required: false

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The schema explicitly requests an auth_token as a raw string input, which creates a credential-handling surface inside the skill interface. Passing bearer-style access tokens through skill parameters increases the risk of token exposure via logs, prompts, telemetry, error messages, or downstream misuse, especially because the skill bridges multiple enterprise platforms and may access calendars, approvals, documents, and tasks.

Content

Scanner excerpt · schema.json (reported line 19)May include surrounding context.

json
},
      "auth_token": {
        "type": "string",
        "description": "平台应用访问凭证(App Access Token / Tenant Access Token)"
      },
      "query_context": {
        "type": "string",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to obtain and pass high-privilege enterprise access tokens such as tenant_access_token and access_token, but does not warn about secure storage, least-privilege scoping, redaction in logs, or secret rotation. In an agent skill context, this is risky because users may paste live credentials into prompts, configs, or telemetry paths, leading to token leakage and unauthorized access to calendars, approvals, documents, or workflow data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest text is entirely in Chinese and does not offer any language choice or explain that the skill is intended only for a Chinese-speaking or region-specific environment. This creates a natural-language locale policy issue because the skill appears to impose a specific language without explicit user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The README presents the skill description and setup instructions entirely in Chinese, which can amount to a language policy issue when no user choice or locale justification is provided. There is no indication that the skill is intentionally restricted to a Chinese-speaking or China-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.