Back to skill

Security audit

self-backup-to-feishu

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent backup-and-restore purpose, but it handles credentials, persistent memory, and cron jobs with too little scoping or user control.

Install only if you are comfortable with a skill that may gather and restore highly sensitive assistant state, email configuration, and scheduled tasks. Before use, remove .msmtprc and unrelated cron data from the backup scope, require explicit approval for every restore target, and avoid restoring cron or behavior-rule files from a Feishu document unless you can verify its provenance and contents.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/daily-backup.py:91
Finding

Plaintext Email Credentials Are Staged for Cloud Synchronization

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/daily-backup.py:75
Finding

Complete User Crontab Is Collected Beyond the Required Backup Scope

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
references/recovery-guide.md:15
Finding

Untrusted Cloud Content Can Replace Persistent Agent Memory and Behavioral Rules

Content
View full analysis
``` ```text The backup document contains the following sections: - Identity information → IDENTITY.md - User information → USER.md - Soul definition → SOUL.md - Complete memory content → MEMORY.md - Email configuration → .msmtprc - Automated tasks → cron ``` ```text Write the extracted content to the corresponding files: | Section | Target file | Description | | Identity information | IDENTITY.md | AI identity definition | | User information | USER.md | User preference configuration | | Soul definition | SOUL.md | AI behavioral rules | | Complete memory content | MEMORY.md | Long-term memory | | Email configuration | ~/.msmtprc | Email-sending configuration | ``` The corresponding declared recovery workflow in `SKILL.md:65-72` instructs the Agent to parse the Feishu document and rebuild `MEMORY.md`, `IDENTITY.md`, `USER.md`, `SOUL.md`, `.msmtprc`, and cron tasks. ### Technical Analysis The recovery workflow treats Feishu document content as authoritative persistent state. It directs the Agent to copy document sections into identity, user-preference, behavioral-rule, and long-term-memory files without requiring cryptographic integrity verification, trusted provenance, schema validation, content sanitization, a local policy baseline, or per-file user approval. Anyone able to modify or replace the Feishu backup document can insert attacker-controlled instructions into `SOUL.md` or false persistent context into `MEMORY.md`. Those files may continue influencing later sessions after the recovery operation has completed. This is distinct from ordinary data resto ...[truncated 1303 chars]
Remediation
View remediation

T06 · System Persistence

Error
Location
references/recovery-guide.md:45
Finding

Cloud-Sourced Cron Entries Can Be Restored as Persistent Commands Without Validation

Content
View full analysis
/dev/null; echo "0 3 * * * /usr/bin/python3 /path/to/script.py") | crontab - ``` ``` ### Technical Analysis The documented recovery procedure directs the Agent to extract cron tasks from a Feishu document and add them to the user's crontab. The shown command appends an example backup task, but the surrounding instructions state that tasks from the backup section should be restored line by line. No command allowlist, trusted path validation, integrity verification, duplicate detection, ownership marker, diff review, or explicit confirmation is required. Because cron executes commands across sessions with the privileges of the owning user, restoring arbitrary cloud-provided cron text creates a persistence channel. Scheduling one known backup command can be legitimate for automatic-backup functionality. Restoring every externally supplied command is broader than necessary and violates least privilege. ### Attack Path 1. An attacker obtains edit access to the Feishu backup document or substitutes a malicious document token. 2. The attacker adds a cron line that invokes an attacker-selected local command, script, interpreter expression, or network client. 3. The user asks the Agent to restore state. 4. The Agent extracts the cron section and appends its entries using `crontab`. 5. The malicious entry survives the recovery session. 6. Cron executes the command at the attacker-selected schedule with the privileges of the affected user. 7. The command continues to run until the entry is discovered and removed. ### Impact Assessment Successful exploitation provides cross-sess ...[truncated 426 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (27)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

A second behavior mismatch exists because the skill advertises automated Feishu backup, restore, and synchronization capabilities that are not actually implemented, creating deceptive expectations around where data goes and what actions occur. That kind of mismatch undermines informed consent and can conceal sensitive local staging or persistence behavior from the user.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

A second behavior mismatch exists because the skill advertises automated Feishu backup, restore, and synchronization capabilities that are not actually implemented, creating deceptive expectations around where data goes and what actions occur. That kind of mismatch undermines informed consent and can conceal sensitive local staging or persistence behavior from the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill proposes backing up identity, user information, memory, email configuration, and cron data without a prominent user-facing warning about confidentiality and account-security implications. Sensitive credentials and personal data stored in a cloud document or backup artifact materially increase the risk of account compromise and privacy breach.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill normalizes backing up highly sensitive user and system data, including memory and email configuration, to an external document store. Even if framed as convenience, centralizing these artifacts creates a concentrated target for exfiltration and can expose credentials, personal history, and operational details.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The restore workflow includes reconstructing files and restoring cron tasks, which can overwrite local state and reintroduce scheduled execution, but it lacks a clear warning about destructive or system-modifying effects. Restoring from an external document without strong warnings and validation can also import stale, tampered, or unsafe configuration.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The recovery flow encourages reading communication-history backups and reconstructing sensitive files from external storage, which normalizes persistent retention and reuse of prior user data. In context, this is especially dangerous because it can rehydrate private information and system configuration into a live environment without strong authenticity, minimization, or consent controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document instructs the agent to overwrite local files and restore cron tasks without any prior warning, diff, or confirmation step. High-impact writes sourced from an external document create a straightforward path to destructive changes, credential replacement, or persistence if the backup is stale, malicious, or misidentified.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
81% confidence
Finding

The YARA hit is not proof of malware, but it correctly highlights a persistence pattern: appending commands into crontab. In the context of a restore guide that imports remote document content into system scheduling, this is dangerous because the mechanism could be abused to establish unauthorized recurring execution.

Content

Scanner excerpt · references/recovery-guide.md (reported line 51)May include surrounding context.

�息 | IDENTITY.md | AI 身份定义 | | 二、用户信息 | USER.md | 用户偏好配置 | | 三、灵魂定义 | SOUL.md | AI 行为准则 | | 四、完整记忆内容 | MEMORY.md | 长期记忆 | | 五、邮箱配置 | ~/.msmtprc | 邮箱发信配置 |

步骤 4:恢复自动化任务

从「六、自动化任务」章节提取 cron 任务,逐行添加:

bash
# 添加 cron 任务
(crontab -l 2>/dev/null; echo "0 3 * * * /usr/bin/python3 /path/to/script.py") | crontab -

步骤 5:验证完整性

检查以下文件是否存在且非空:

  • MEMORY.md
  • IDENTITY.md
  • USER.md
  • SOUL.md
  • ~/.msmtprc(如果文档中有)
  • cron 任务列表

步骤 6:读取沟通历史(可选)

如果文档中记录了沟通历史备份文档链接:

  1. 读取沟通历史备份文档
  2. 了解历史对话和情感连接
  3. 补充上下文记忆

错误处理

文档不存在

  • 提示用户:未找到备份文档,无法恢复
  • 建议�

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Collecting .msmtprc is unjustified for a Feishu-based AI state backup and may expose SMTP usernames, passwords, tokens, or server details. Because the skill is framed as assistant-memory synchronization, users are less likely to expect credential material to be swept into backup artifacts, making the data exposure particularly risky.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The stated skill purpose is AI state backup, but the generated backup also includes .msmtprc contents and cron jobs, expanding collection into system and credential-adjacent data without clear necessity. In this skill context, that over-collection is more dangerous because the backup is intended for synchronization/restoration, increasing the chance that secrets and host configuration are replicated into broader storage or later exposed.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script assembles sensitive identity, user, memory, soul, email, and automation data into a natural-language restoration document designed for later replay. This creates a single highly concentrated artifact that is easy to exfiltrate, sync to third parties, or misuse for impersonation and environment reconstruction; the restore instructions further increase abuse potential by making rehydration straightforward.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes file reads/writes and shell-driven automation but declares no explicit tool scope or permissions boundaries. That increases the chance an agent can invoke sensitive capabilities implicitly, especially because the skill also handles restoration and cron-related operations that can modify system state.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough that ordinary conversation about backup, restore, or sync could invoke a skill that reads and writes highly sensitive state. Because the skill can affect memory, credentials, and system automation, accidental activation materially raises privacy and integrity risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Automatic backup conditions like learning a new skill, completing automation, or adding an important contact are vague and can cause background collection without a clear, contemporaneous user request. In this context, that means sensitive memory and system data could be persisted or staged more often than the user expects.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Recommending both state backups and communication-history backups to keep memory complete encourages long-term retention of user interactions beyond what is necessary for normal operation. This increases privacy risk, expands breach impact, and makes overcollection seem like best practice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad and overlap with normal memory/sync requests, increasing the chance the skill runs when the user did not intend a destructive restore workflow. In this skill, accidental activation is more dangerous because the workflow includes overwriting files and installing cron jobs from remote content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The recovery guide restores sensitive system-level artifacts beyond conversational state, including ~/.msmtprc and cron entries. Because the content is pulled from a remotely stored Feishu document and then written locally, a tampered backup could implant mail credentials or persistence mechanisms under the guise of state recovery.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

Using crontab to append tasks establishes persistent behavior on the host, which is a sensitive capability in an agent skill. Here that persistence is driven by backup document contents, so a malicious or compromised document could cause recurring execution of attacker-controlled commands after the restore completes.

Content

Scanner excerpt · references/recovery-guide.md (reported line 51)May include surrounding context.

bash
# 添加 cron 任务
(crontab -l 2>/dev/null; echo "0 3 * * * /usr/bin/python3 /path/to/script.py") | crontab -

步骤 5:验证完整性

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script advertises automatic Feishu backup, but it never uploads anything to Feishu and only writes a local backup plus a pending-sync marker. This is dangerous because users may believe they have an off-device recovery backup when in fact sensitive state remains only on the local host, creating a false sense of resilience and possible data-loss during restore scenarios.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The docstring claims automatic backup to a Feishu document, but the implementation only stages local files for future sync. This mismatch can mislead operators into assuming remote persistence and may cause them to handle or delete local state unsafely under the false belief that a remote backup already exists.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Enumerating cron jobs is outside the clearly stated scope of backing up AI assistant memory and can reveal other scheduled tasks, paths, credentials, or operational details unrelated to the skill. In a sync/backup context, this broadens host reconnaissance and leaks system metadata that could aid later targeting.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/daily-backup.py (reported line 78)May include surrounding context.

python
def get_cron_jobs():
    """获取当前 cron 任务"""
    try:
        result = subprocess.run(["crontab", "-l"], capture_output=True, text=True)
        if result.returncode == 0:
            return result.stdout
        return "# 无 cron 任务"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script serializes sensitive email configuration into backup content without any explicit warning, consent prompt, or redaction step. This increases the likelihood that credential material is silently copied into backup artifacts that may later be synced, shared, or restored in insecure contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script writes a consolidated backup containing user memory, identity data, and sensitive configuration to disk without prominently disclosing the sensitivity or applying protections such as restrictive permissions or encryption. In this skill context, the file becomes a high-value local aggregation point for private data and credential-adjacent material.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's docstring, usage examples, log messages, and CLI output are written entirely in Chinese, which imposes a specific language on users. Under the policy, locale or language restrictions should either be optional or clearly justified as region-specific; neither is present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.