Back to skill

Security audit

Feishu CRM Lite

Security checks for vulnerabilities and agentic risk

Overview

The skill is a CRM helper, but it under-discloses that customer data is stored locally in plaintext and its documentation overstates Feishu integration that is not implemented.

Install only if you are comfortable with customer and follow-up data being kept as local plaintext files under data/feishu-crm, not in Feishu Bitable as documented. Run it from a private workspace, avoid adding regulated or highly sensitive customer details, and require explicit confirmation before deleting records or doing bulk import/export until the storage model and Feishu integration are clarified.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:53
Finding

CRM Personally Identifiable Information Stored in Plaintext Files with Implicit Permissions

Content
View full analysis
c.status === filters.status); } if (filters.tag) { customers = customers.filter(c => c.tags.includes(filters.tag)); } if (filters.source) { customers = customers.filter(c => c.source === filters.source); } return customers; } saveCustomers(customers) { fs.writeFileSync(this.customersFile, JSON.stringify(customers, null, 2)); } ``` ```js getFollowUps(customerId = null) { const data = fs.readFileSync(this.followUpsFile, 'utf8'); let followUps = JSON.parse(data); if (customerId) { followUps = followUps.filter(f => f.customerId === customerId ...[truncated 3697 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README states the skill can be used immediately with no extra configuration, while the development checklist later shows core CRM, follow-up, reminder, funnel, and analytics features are not yet implemented. This mismatch can mislead users into trusting and invoking actions that do not exist or may behave unpredictably, increasing the chance of operational mistakes or unsafe assumptions about data handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises potentially state-changing operations such as creating, updating, deleting, importing/exporting customer records, and setting reminders without any warning about modifying user data or triggering external effects. In an agent context, lack of disclosure and confirmation guidance can cause users to invoke destructive or privacy-sensitive actions without understanding the consequences.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes very broad everyday terms such as '提醒', '销售', '客户管理', and 'customer', which increases the chance the skill activates in unrelated conversations. In a skill that claims the ability to create, update, delete, and store customer records, accidental invocation could lead to unintended data access or modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description describes customer record creation, update, deletion, import/export, and storage in Feishu Bitable without warning users that business contact data will be persisted and modified. Because CRM data often contains personal and commercial information, missing consent, retention, and modification warnings increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill says it archives communication content and uses existing Feishu API permissions, but it does not disclose the privacy implications of storing conversation details or the scope of access granted through those permissions. Archiving follow-up notes can capture sensitive personal, commercial, or regulated information, making silent collection and retention risky.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises Feishu CRM capabilities such as Bitable-backed storage, customer management, follow-up tracking, reminders, and analytics as available features, while the development status explicitly says those core integrations and functions are not yet implemented. This can mislead users into relying on nonexistent functionality for customer data handling or business workflows, creating integrity and operational risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code initializes and writes persistent files for customers, follow-ups, and reminders, which contain potentially sensitive business contact information. Although the file has code comments, there is no user-facing disclosure, confirmation, or CLI warning that customer data will be stored on disk under the current working directory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The deleteCustomer method irreversibly removes customer records from persisted storage, but there is no confirmation prompt, warning message, or explicit disclosure of this destructive behavior. Code comments alone do not warn end users, and this operation could result in accidental data loss if exposed through a skill action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

SQP-3 applies to natural-language policy issues in all file types. The file presents all instructions and examples only in Chinese and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

All natural-language instructions, headings, and examples are presented in Chinese, and the file does not indicate that the skill is intentionally limited to Chinese-speaking users or a specific locale. Under the stated policy, forcing a specific language without user opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language description and CLI output strings are Chinese-only, which can impose a language/locale choice on users without opt-in. The policy calls for flagging skills that force a specific language unless they clearly offer a choice or justify the locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.