Back to skill

Security audit

飞书群聊安全隔离

Security checks for vulnerabilities and agentic risk

Overview

This skill is presented as a Feishu chat security layer, but it grants very broad owner powers and can bind that owner from weak or first-contact sources without enough enforcement evidence.

Install only if you can preconfigure and verify the Feishu owner ID before the bot is reachable, and do not rely on this package as the sole enforcement layer for file access, shell commands, or skill installation. Review the first-contact binding behavior and require a real runtime authorization gate before using it in shared or production chat environments.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:23
Finding

Non-Overridable Skill Instructions Grant Unrestricted Owner Privileges

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:43
Finding

First Private-Message Sender Can Acquire the Privileged Owner Role

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
verify.sh:108
Finding

Verifier Reports Static Policy Configuration as Active Security Enforcement

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (25)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 304)May include surrounding context.

*.pem *.p12 *.pfx .env .env.

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 287)May include surrounding context.

md
"~/.gnupg/",
    "~/.aws/",
    "~/.openclaw/credentials/",
    "/etc/passwd",
    "/etc/shadow",
    "/proc/self/environ",
    "/proc/self/cmdline",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config.json (reported line 47)May include surrounding context.

json
"~/.gnupg/",
    "~/.aws/",
    "~/.openclaw/credentials/",
    "/etc/passwd",
    "/etc/shadow",
    "/proc/self/environ",
    "/proc/self/cmdline",

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 288)May include surrounding context.

md
"~/.aws/",
    "~/.openclaw/credentials/",
    "/etc/passwd",
    "/etc/shadow",
    "/proc/self/environ",
    "/proc/self/cmdline",
    "/var/log/",

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config.json (reported line 48)May include surrounding context.

json
"~/.aws/",
    "~/.openclaw/credentials/",
    "/etc/passwd",
    "/etc/shadow",
    "/proc/self/environ",
    "/proc/self/cmdline",
    "/var/log/",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config.json (reported line 60)May include surrounding context.

json
"*.pem",
    "*.p12",
    "*.pfx",
    "*.env",
    ".env.*"
  ],
  "injection_keywords": {

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README presents all user-facing instructions, expected replies, and trigger commands exclusively in Chinese, such as "绑定主人" and "安装技能 xxx". Under the policy, forcing a specific language without user opt-in is a natural-language locale constraint and should be flagged unless the skill offers alternatives or clearly documents a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes shell-capable behavior such as executing system commands, reading/modifying files, and includes executable Python snippets, but it does not declare any explicit tool scope or allowed-tools policy. In an agent framework, missing tool declarations can cause over-broad execution capability or bypass policy enforcement, especially for a security-focused skill that is expected to constrain rather than expand execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The owner-binding flow is triggered by vague natural-language phrases like '绑定主人' or similar wording, which can be matched accidentally in ordinary conversation or socially engineered by another user. Because this path controls ownership establishment, ambiguous triggering increases the chance of unintended privileged state transitions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language command keywords for owner and skill-install actions are predominantly Chinese phrases, which implies the skill recognizes or expects a specific language. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

All user-visible messages and instructions in the script are presented only in Chinese, including installation status and next-step guidance. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in or an explicitly documented justification.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 37)May include surrounding context.

sh
setup_directories() {
    print_info "创建目录结构..."
    mkdir -p "${SCRIPT_DIR}/logs"
    chmod 700 "${SCRIPT_DIR}"
    chmod 750 "${SCRIPT_DIR}/logs"
    print_success "目录创建完成"
}

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 38)May include surrounding context.

sh
print_info "创建目录结构..."
    mkdir -p "${SCRIPT_DIR}/logs"
    chmod 700 "${SCRIPT_DIR}"
    chmod 750 "${SCRIPT_DIR}/logs"
    print_success "目录创建完成"
}

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · verify.sh (reported line 162)May include surrounding context.

sh
print_info "创建目录结构..."
    mkdir -p "${SCRIPT_DIR}/logs"
    chmod 700 "${SCRIPT_DIR}"
    chmod 750 "${SCRIPT_DIR}/logs"
    print_success "目录创建完成"
}

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The installer automatically pulls an owner identifier from unrelated local state (~/.openclaw/openclaw.json) or FEISHU_OWNER_ID and then uses it to bind and lock the skill configuration. This creates a trust-boundary violation: local ambient data is treated as authoritative identity without explicit user confirmation, so a stale, wrong, or attacker-influenced value could silently assign control of the skill to the wrong account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script consumes local config and environment data for security-sensitive owner binding without a user-facing warning or consent step. In an installation context for a chat-security skill, silent identity capture is risky because users may not realize ambient machine state is being used to define who controls the bot.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 92)May include surrounding context.

sh
set_permissions() {
    print_info "设置文件权限..."
    chmod 600 "${SCRIPT_DIR}/config.json"
    print_success "权限设置完成"
}

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · verify.sh (reported line 185)May include surrounding context.

sh
set_permissions() {
    print_info "设置文件权限..."
    chmod 600 "${SCRIPT_DIR}/config.json"
    print_success "权限设置完成"
}

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · verify.sh (reported line 280)May include surrounding context.

sh
set_permissions() {
    print_info "设置文件权限..."
    chmod 600 "${SCRIPT_DIR}/config.json"
    print_success "权限设置完成"
}

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 100)May include surrounding context.

sh
print_info "初始化日志文件..."
    LOG_FILE="${SCRIPT_DIR}/logs/security.log"
    touch "$LOG_FILE"
    chmod 640 "$LOG_FILE"
    
    cat >> "$LOG_FILE" << EOF
[$(date '+%Y-%m-%d %H:%M:%S')] [INFO] 飞书群聊安全隔离 Skill v2.0.0 初始化

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · verify.sh (reported line 168)May include surrounding context.

sh
print_info "初始化日志文件..."
    LOG_FILE="${SCRIPT_DIR}/logs/security.log"
    touch "$LOG_FILE"
    chmod 640 "$LOG_FILE"
    
    cat >> "$LOG_FILE" << EOF
[$(date '+%Y-%m-%d %H:%M:%S')] [INFO] 飞书群聊安全隔离 Skill v2.0.0 初始化

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's header, usage guidance, and all user-facing instructions are written exclusively in Chinese, and later operational guidance requires exact Chinese phrases such as "绑定主人" and "查看主人". This imposes a language requirement on users without any opt-in, alternative locale, or documented regional justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manual verification checklist says the owner installing a skill should 'directly install successfully', which conflicts with the script's earlier requirement that skill installation approval be enabled. In a security-sensitive verification tool, contradictory operational guidance can cause testers to validate an insecure workflow or normalize bypassing approval controls, weakening the intended access-control model.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The installation flow uses broad natural-language invocation like '安装技能 xxx' without a tightly defined command grammar. That can cause accidental installs from normal discussion text or make approval workflows easier to manipulate through phrasing collisions, although the owner-approval step reduces severity.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The comments imply secure owner identification will be handled later via Feishu API, but the installer already performs owner binding from weaker sources and marks the security state as BOUND and locked = true. This mismatch can mislead operators into believing binding is deferred or verified when, in fact, it already occurred based on unverified local data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.