Back to skill

Security audit

Active Learning Agent

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Feishu productivity assistant, but it continuously scans private workplace data, stores long-term notes, and can send or create content without clear approval controls.

Install only if you are comfortable granting a recurring assistant broad Feishu visibility. Before enabling it, restrict which chats, documents, meetings, recordings, and calendars it may inspect, require approval before it sends messages or creates documents, and decide how the memory and log files can be reviewed, redacted, and deleted.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README explicitly describes broad, ongoing access to highly sensitive workplace data sources, including private messages, meeting transcripts, documents, and calendars, but provides no visible consent model, access scoping, retention limits, or privacy warning. In an agent skill, this creates a real risk of over-collection, surveillance, and secondary use of sensitive information well beyond what users may reasonably expect.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill explicitly promotes 'full-source perception' across group chats, private chats, meeting transcripts, documents, and calendars to build a long-term information graph, but it does not present a clear user-facing notice, consent flow, or scoped permission model. This creates covert surveillance risk and enables collection of sensitive work and personal communications far beyond what a user would reasonably expect from a helper skill.

Missing User Warnings

High
Confidence
99% confidence
Finding
The cron configuration runs every 2 hours and automatically announces results to Feishu, effectively creating ongoing autonomous monitoring and outbound reporting. Without an explicit warning, consent checkpoint, or approval-before-send control, the skill can continuously inspect private/work data and push derived conclusions to external channels without the user's contemporaneous awareness.

Ssd 3

Medium
Confidence
96% confidence
Finding
This example explicitly endorses aggregating information from group chats, private chats, meetings, documents, and historical records to build a user-centric timeline. That creates a surveillance-style capability that can expose sensitive personal or organizational context far beyond the minimum needed for a task, especially if users whose data is traversed did not consent to this cross-source profiling.

Ssd 3

Medium
Confidence
97% confidence
Finding
The outbound alert example includes a user's quoted statement, a meeting recording timestamp, and chat timing details drawn from multiple sources. Emitting this kind of correlated evidence can leak sensitive speech and activity metadata to recipients who may not be entitled to hear meeting-recording details or private contextual inferences.

Ssd 3

Medium
Confidence
95% confidence
Finding
This workflow takes meeting notes and audio discussion segments, extracts content, and republishes it into a new document without describing consent, access checks, or retention limits. That kind of transformation and redistribution can amplify exposure by moving sensitive meeting content into a broader-access artifact, increasing the risk of unauthorized disclosure and secondary sharing.

Ssd 3

High
Confidence
99% confidence
Finding
The skill instructs the agent to broadly collect and correlate user data from chats, DMs, meeting notes, transcripts, documents, and calendars, then reuse it for insights and actions. This is dangerous because it centralizes sensitive communications into a persistent cross-context profile, increasing the blast radius of any misuse, overreach, or data leak.

Ssd 3

High
Confidence
99% confidence
Finding
The deep-tracing workflow explicitly tells the agent to inspect private messages and older discussions for additional hidden context, including 'real thoughts' not expressed elsewhere. That instruction is especially dangerous because it encourages invasive inference and retrieval of confidential material that participants may have intentionally kept compartmentalized, enabling privacy violations, workplace harm, and unauthorized disclosure.

Ssd 3

High
Confidence
98% confidence
Finding
The insight journal design normalizes persistent storage of cross-source observations, including private-chat references, long-term timelines, and linked interpretations across meetings, docs, and chats. Persistent aggregation of this kind materially increases privacy risk because sensitive fragments become searchable, durable profiles that can outlive the original context and be reused in later outputs.

Ssd 3

Medium
Confidence
94% confidence
Finding
The post-response handling instructs the agent to extract user understanding and store it in MEMORY.md, creating ongoing accumulation of behavioral and preference data. While less severe than the broad source scanning, it still enables silent long-term profiling and can cause future overpersonalization, privacy loss, or propagation of incorrect inferences across sessions.

Ssd 3

High
Confidence
97% confidence
Finding
The skill description explicitly directs continuous observation of a user’s chats, private messages, meeting notes, recordings, documents, and calendar to build timelines and proactively act. This creates a broad surveillance and aggregation capability that can collect far more sensitive data than is necessary, increasing the risk of privacy violations, unauthorized profiling, and misuse of confidential information.

Ssd 3

High
Confidence
98% confidence
Finding
The workflow instructs the agent to retrospectively search across meeting notes, recordings, documents, and historical discussions, then update timelines, take actions, send messages, and write logs. This combination of broad retrospective search, autonomous action, and persistent logging is dangerous because it enables sensitive cross-source correlation and downstream disclosure or action without clear consent boundaries or need-to-know limitations.

Static analysis

No suspicious patterns detected.