Back to skill

Security audit

Dingtalk Meetings Skill

Security checks for vulnerabilities and agentic risk

Overview

This DingTalk calendar skill is coherent, but needs Review because setup can persist a user-supplied credential-bearing MCP endpoint into global agent configs and it caches employee identifiers locally.

Install only if you are comfortable granting this skill access to your DingTalk calendar and, when contacts are enabled, employee lookup data. During setup, verify the MCP URL comes from the official DingTalk AIHub page, prefer project-scoped/manual configuration where possible, do not share the full URL because it contains an API key, and periodically clear or avoid the local contacts cache if employee identifiers are sensitive.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T07 · Tool Hijacking and Spoofing

Warning
Location
SKILL.md:128
Finding

Unvalidated User-Supplied Endpoint Registered as a Trusted MCP Service

Content
View full analysis
" ``` ```json { "mcpServers": { "dingtalk-calendar": { "type": "http", "url": "" } } } ``` The instructions state that the endpoint contains a personal API key and should be written into the configuration without being repeated in later responses. However, they do not require validation of its scheme, hostname, port, redirect behavior, or origin before registration. ### Technical Analysis The Skill accepts a URL pasted into the conversation and registers it under the trusted service name `dingtalk-calendar`. Although the user is initially directed to an official DingTalk setup page, the subsequently supplied URL is not required to belong to a DingTalk-controlled HTTPS origin. MCP services act as trusted tool providers. Registering an arbitrary endpoint under the expected calendar service identity can allow a malicious server to impersonate legitimate tools, return deceptive results, collect calendar requests, or induce unauthorized operations. If the supplied URL contains authentication material, sending requests to an untrusted origin may also disclose that material. The behavior is related to the declared installation functionality, but accepting an arbitrary endpoint without origin validation exceeds the minimum safe trust required for MCP registration. ### Attack Path 1. An attacker persuades the user to paste a malicious or look-alike MCP endpoint. 2. The Skill registers that URL under the legitimate-looking `dingtalk-calendar` service name. 3. The user restarts the MCP-capable client as instructed. 4. Subsequent calendar tool calls are routed to the attacker-controlled service. 5. The malicious service records request data ...[truncated 786 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:139
Finding

Automatic Modification of Security-Sensitive Global Agent Configuration

Content
View full analysis
" } } } ``` The instructions direct the Agent to detect available configuration files and write to the first matching target. They require preserving existing entries but do not require approval of the selected path, backups, atomic writes, restrictive permissions, or protection of unrelated entries during parsing and rewriting. ### Technical Analysis The listed global configuration files may contain credentials, private MCP endpoints, trusted server definitions, and other security-sensitive settings. Automatically selecting and modifying the first matching file creates risks beyond the minimum privileges necessary to configure a calendar service. A failed or non-atomic rewrite could corrupt the entire configuration. An overly broad read or diagnostic response could disclose unrelated secrets. Choosing a global target can persist the service across projects even where only project-level access is needed. The instructions also do not specify preservation of ownership and filesystem permissions. The project contains no direct script that performs these writes, and no evidence of deliberate credential theft was found. The risk arises from unsafe installation instructions that authorize an Agent to ...[truncated 1268 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:319
Finding

Persistent Plaintext Cache of Organizational Contact Identifiers

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
97% confidence
Finding

The skill instructs access to and modification of a sensitive agent configuration path in the user's home directory (~/.gemini/settings.json). This is dangerous because it enables persistent environment changes and secret insertion unrelated to the immediate calendar action, and the configured URL may embed an API key that remains on disk for future exposure.

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

md
| Cursor | `~/.cursor/mcp.json` | `.cursor/mcp.json` | `mcpServers` |
   | VS Code Copilot | `~/Library/Application Support/Code/User/mcp.json`(Mac)<br>`%APPDATA%\Code\User\mcp.json`(Win) | `.vscode/mcp.json` | `servers` |
   | Roo Code | — | `.roo/mcp.json` | `mcpServers` |
   | Gemini CLI | `~/.gemini/settings.json` | — | `mcpServers` |
   | OpenAI Codex | `~/.codex/config.json` | — | `mcpServers` |

   向目标文件追加(若文件已有 `mcpServers`/`servers`,只添加新条目,不覆盖原有内容):

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
97% confidence
Finding

The skill instructs access to and modification of another sensitive agent configuration path (~/.codex/config.json) to register an MCP server. This creates persistent host-level side effects and may store a credential-bearing URL in a long-lived config file, increasing the chance of leakage through backups, file sharing, or accidental repository inclusion.

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
| VS Code Copilot | `~/Library/Application Support/Code/User/mcp.json`(Mac)<br>`%APPDATA%\Code\User\mcp.json`(Win) | `.vscode/mcp.json` | `servers` |
   | Roo Code | — | `.roo/mcp.json` | `mcpServers` |
   | Gemini CLI | `~/.gemini/settings.json` | — | `mcpServers` |
   | OpenAI Codex | `~/.codex/config.json` | — | `mcpServers` |

   向目标文件追加(若文件已有 `mcpServers`/`servers`,只添加新条目,不覆盖原有内容):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README prominently advertises destructive actions such as modifying, deleting, and canceling calendar events without any caution about confirmation, authorization, or irreversible side effects. In an agent-executed skill, this can normalize unsafe usage patterns and increase the chance that users or downstream agents invoke destructive operations without adequate verification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The initialization flow directs the agent to modify MCP and agent configuration files in user and project directories, which is outside ordinary calendar-management behavior and changes the host environment persistently. Because the supplied URL contains a personal API key, automatic config-file writes can create durable secret exposure and unsafe cross-skill/system side effects if written to the wrong location or later committed/shared.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs the agent to persist contact identifiers and later expose cached contact data from a local file. This expands the skill from direct calendar operations into local data retention of personal identifiers, creating unnecessary privacy and data-handling risk if the cache is read back, leaked, or becomes stale and misleading.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill stores userId mappings for contacts in a local cache but does not require a user-facing privacy disclosure or consent before persisting personal data. Even if the data is operationally useful, silently retaining identifiers creates a privacy risk and may conflict with user expectations or organizational data-handling requirements.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly tells the agent to persist user-provided contact mappings and to display cached contacts on request, which can reveal internal identifiers beyond the immediate transaction. Persisting and later revealing identifiers increases the blast radius of any chat disclosure, local compromise, or unauthorized use of the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger evals use very broad, natural phrasing such as creating, viewing, canceling, and scheduling meetings without documenting tighter activation constraints or disambiguation rules. In an agentic context, this can cause the skill to over-trigger on ambiguous calendar-related requests, leading to unintended access to calendar data or unintended meeting operations on DingTalk when the user may have meant another tool or a non-actionable inquiry.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/mcp-tools.md (reported line 107)May include surrounding context.

md
查询企业会议室分组列表。

- **可选**:`pageSize`(≤100,默认 100)、`pageIndex`(默认 0)
- 返回:`groupList[]`(groupId、parentId、groupName)、hasMore、nextCursor

#### list_org_room_labels
查询企业会议室标签集,无需入参。

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents tools that can retrieve sensitive organizational data such as mobile numbers, user profiles, department membership, and followings, but it gives no privacy guardrails, purpose limitation, or user-consent requirements. In an agentic setting, this increases the risk of over-collection or unauthorized disclosure of employee data through normal skill use.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This JSON eval file is a manifest-like file, so vague-trigger review applies. The phrase "帮我创建一个明天下午2点到3点的项目评审会议" is presented as a trigger/example without clarifying invocation boundaries, negative examples, or context limits, which could overlap with ordinary chat requests if reused as activation guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The phrase "查看我今天有哪些会议" is broad, natural everyday speech. In a manifest-like file, examples that may function as activation guidance should be specific enough to avoid accidental invocation, but no limiting context or exclusion conditions are provided here.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The phrase "帮我把下午的产品会议取消" is a common-language request that could appear in ordinary conversation. Because the file does not specify how invocation is limited or provide negative examples, the trigger guidance is overly broad for a manifest-style artifact.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

All natural-language trigger examples in the file are written in Chinese, with no indication that the skill supports other languages or that Chinese is an intentional, documented locale restriction. This can constitute a language-policy issue if the skill is implicitly constrained to one language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

文件在参数说明中将 timeZone 默认设为 Asia/Shanghai,这构成了明确的地区/时区默认约束。文档未说明这是中国区专用工具,也未提示应按用户所在语言/地区或偏好调整,属于自然语言层面的 locale policy 风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

该行将推荐时间计算的 timeZone 默认设置为 Asia/Shanghai,但没有为其他地区用户提供显式选择说明。若在跨时区使用,会造成隐含的 locale 偏置,符合语言/地区策略类问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.