Back to skill

Security audit

Feishu Comments

Security checks for vulnerabilities and agentic risk

Overview

The skill is advertised as read-only comment reading, but bundled scripts can close comments and include unsafe handling that could execute code from document content.

Review this skill before installing. Use only credentials with the minimum Feishu/Lark permissions, avoid granting comment-write permission to a read-only comment tool, and do not run the bundled resolver unless you intend to close comments. The unsafe Python interpolation should be fixed before use on documents that other people can edit.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/get_comments.sh:119
Finding

Arbitrary Python Code Execution Through Unsafe Data Interpolation

Content
View full analysis
/dev/null || echo "") ``` ### Technical Analysis The script inserts remote document content directly into Python source supplied to `python3 -c`: ```python doc_content = '''${DOC_CONTENT}''' ``` Shell expansion occurs before Python parses the program. Consequently, `DOC_CONTENT` is treated as source text rather than as an inert data value. A document containing a triple-quote terminator followed by valid Python statements can escape the intended string literal and inject arbitrary Python code. The third command-line argument, stored in `SHOW_ALL`, is similarly inserted into a single-quoted Python expression without validation: ```python show_all = '${SHOW_ALL}' == '--all' ``` A malicious argument containing a quote and Python statements can therefore alter the generated program. Shell quoting around the outer `python3 -c` command does not prevent this issue because the expansion remains part of the Python source string. ### Attack Path #### Remote document-content path 1. An attacker gains the ability to create or edit content in a Feishu/L ...[truncated 1804 chars]
Remediation
View remediation
&2 exit 2 ;; esac ``` 4. If environment variables are used, read them only as data: ```bash DOC_CONTENT="$DOC_CONTENT" SHOW_ALL="$SHOW_ALL" \ python3 -c ' import os doc_content = os.environ.get("DOC_CONTENT", "") show_all = os.environ.get("SHOW_ALL", "") == "--all" # Continue processing without evaluating either value. ' ``` 5. A JSON-based approach is preferable for large document bodies and should avoid operating-system environment-size limits. 6. Add regression tests containing triple quotes, single quotes, backslashes, newlines, Unicode, and code-like strings. Verify that none are interpreted as Python. 7. Run the script with the least-privileged operating-system account and narrowly scoped Feishu/Lark permissions to reduce the impact of any future injection flaw. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/resolve_comments.sh:102
Finding

Undeclared Comment-Mutation Capability Violates the Skill's Read-Only Scope

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says the skill is for reading/fetching comments on a Feishu document. The code's primary function is not passive reading: it closes comments by sending PATCH requests with {"is_solved": true}. It also supports an --orphaned mode that retrieves raw document content, analyzes comment quotes against the document text, identifies orphaned unresolved comments, and resolves them automatically. Those are material write/update capabilities and analysis behaviors not represented by the declared description.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/get_comments.sh (reported line 27)May include surrounding context.

sh
fi

# Get tenant_access_token
TOKEN_RESP=$(curl -s -X POST "${API_BASE}/open-apis/auth/v3/tenant_access_token/internal" \
  -H "Content-Type: application/json" \
  -d "{\"app_id\":\"${APP_ID}\",\"app_secret\":\"${APP_SECRET}\"}")

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/get_comments.sh (reported line 56)May include surrounding context.

sh
COMMENT_IDS=""
  fi

  ALL_COMMENTS=$(curl -s -X GET \
    "${API_BASE}/open-apis/drive/v1/files/${DOC_TOKEN}/comments?file_type=docx&user_id_type=open_id" \
    -H "Authorization: Bearer ${TENANT_TOKEN}")

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/get_comments.sh (reported line 91)May include surrounding context.

sh
")

# Batch query comments
RESULT=$(curl -s -X POST \
  "${API_BASE}/open-apis/drive/v1/files/${DOC_TOKEN}/comments/batch_query?file_type=docx&user_id_type=open_id" \
  -H "Authorization: Bearer ${TENANT_TOKEN}" \
  -H "Content-Type: application/json" \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/resolve_comments.sh (reported line 25)May include surrounding context.

sh
fi

# Get tenant_access_token
TENANT_TOKEN=$(curl -s -X POST "${API_BASE}/open-apis/auth/v3/tenant_access_token/internal" \
  -H "Content-Type: application/json" \
  -d "{\"app_id\":\"${APP_ID}\",\"app_secret\":\"${APP_SECRET}\"}" | python3 -c "import sys,json; print(json.load(sys.stdin)['tenant_access_token'])" 2>/dev/null)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/get_comments.sh (reported line 40)May include surrounding context.

sh
# If --orphaned, find orphaned comment IDs automatically
if [ "$TARGET" = "--orphaned" ]; then
  # Get doc content
  DOC_CONTENT=$(curl -s -X GET \
    "${API_BASE}/open-apis/docx/v1/documents/${DOC_TOKEN}/raw_content" \
    -H "Authorization: Bearer ${TENANT_TOKEN}" | python3 -c "
import sys, json

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/resolve_comments.sh (reported line 37)May include surrounding context.

sh
# If --orphaned, find orphaned comment IDs automatically
if [ "$TARGET" = "--orphaned" ]; then
  # Get doc content
  DOC_CONTENT=$(curl -s -X GET \
    "${API_BASE}/open-apis/docx/v1/documents/${DOC_TOKEN}/raw_content" \
    -H "Authorization: Bearer ${TENANT_TOKEN}" | python3 -c "
import sys, json

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/resolve_comments.sh (reported line 46)May include surrounding context.

sh
" 2>/dev/null || echo "")

  # List all comments
  ALL_COMMENTS=$(curl -s -X GET \
    "${API_BASE}/open-apis/drive/v1/files/${DOC_TOKEN}/comments?file_type=docx&user_id_type=open_id" \
    -H "Authorization: Bearer ${TENANT_TOKEN}")

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This script performs state-changing comment resolution even though the skill is described as read-only comment access. That mismatch is dangerous because an agent or user invoking a seemingly safe read-comments skill could unintentionally modify collaboration records and close feedback threads without informed consent.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/resolve_comments.sh (reported line 100)May include surrounding context.

sh
# Resolve each comment
IFS=',' read -ra IDS <<< "$TARGET"
for cid in "${IDS[@]}"; do
  RESP=$(curl -s -X PATCH \
    "${API_BASE}/open-apis/drive/v1/files/${DOC_TOKEN}/comments/${cid}?file_type=docx" \
    -H "Authorization: Bearer ${TENANT_TOKEN}" \
    -H "Content-Type: application/json" \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes shell execution and reads local credentials from ~/.openclaw/openclaw.json, but it does not declare any permissions or allowed-tools scope. That creates an authorization gap where a seemingly simple read-only integration can access local secrets and execute commands without explicit user-visible restriction, increasing the chance of unintended or over-broad execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script reads app credentials from the local OpenClaw config even though the manifest describes a simple comment-reading capability. While this is likely intended to authenticate to Feishu, it expands the skill's effective privilege boundary and is not transparent to the user. In an agent setting, undisclosed access to local secrets is dangerous because users may not expect a comment-reading skill to consume stored credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script extracts appId and appSecret from a local config file and transmits them to an external API to obtain a tenant token, without any disclosure in script output. Even though this is the normal Feishu auth flow, silently exfiltrating local secrets across the network is a meaningful security and privacy concern in a skill whose stated purpose is reading comments. The mismatch between declared purpose and secret access makes this more dangerous in agent environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script fetches raw document content and comments from remote APIs and processes them without any user-facing notice. This is functionally necessary for the feature, but it still transmits potentially sensitive document data and comments to external services and performs additional content retrieval beyond just comments. In collaboration workflows, document content and comments can contain confidential information, so undisclosed transfer increases risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/get_comments.sh (reported line 91)May include surrounding context.

sh
")

# Batch query comments
RESULT=$(curl -s -X POST \
  "${API_BASE}/open-apis/drive/v1/files/${DOC_TOKEN}/comments/batch_query?file_type=docx&user_id_type=open_id" \
  -H "Authorization: Bearer ${TENANT_TOKEN}" \
  -H "Content-Type: application/json" \

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file header clearly advertises comment resolution behavior, which contradicts the documented purpose of the skill. This discrepancy is a security issue because it signals hidden or undeclared write functionality inside a skill users would reasonably trust as read-only.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/get_comments.sh (reported line 27)May include surrounding context.

sh
fi

# Get tenant_access_token
TENANT_TOKEN=$(curl -s -X POST "${API_BASE}/open-apis/auth/v3/tenant_access_token/internal" \
  -H "Content-Type: application/json" \
  -d "{\"app_id\":\"${APP_ID}\",\"app_secret\":\"${APP_SECRET}\"}" | python3 -c "import sys,json; print(json.load(sys.stdin)['tenant_access_token'])" 2>/dev/null)

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/resolve_comments.sh (reported line 25)May include surrounding context.

sh
fi

# Get tenant_access_token
TENANT_TOKEN=$(curl -s -X POST "${API_BASE}/open-apis/auth/v3/tenant_access_token/internal" \
  -H "Content-Type: application/json" \
  -d "{\"app_id\":\"${APP_ID}\",\"app_secret\":\"${APP_SECRET}\"}" | python3 -c "import sys,json; print(json.load(sys.stdin)['tenant_access_token'])" 2>/dev/null)

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/resolve_comments.sh (reported line 65)May include surrounding context.

sh
# Batch query for details
  IDS_JSON=$(echo "$COMMENT_IDS_STR" | python3 -c "import sys,json; print(json.dumps(sys.stdin.read().strip().split(',')))")
  DETAIL=$(curl -s -X POST \
    "${API_BASE}/open-apis/drive/v1/files/${DOC_TOKEN}/comments/batch_query?file_type=docx&user_id_type=open_id" \
    -H "Authorization: Bearer ${TENANT_TOKEN}" \
    -H "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This outbound PATCH request changes remote document state by marking comments resolved. In the context of a skill advertised as read-only, the external transmission is dangerous because it performs undeclared write actions against user content and can alter review records at scale.

Content

Scanner excerpt · scripts/resolve_comments.sh (reported line 100)May include surrounding context.

sh
# Resolve each comment
IFS=',' read -ra IDS <<< "$TARGET"
for cid in "${IDS[@]}"; do
  RESP=$(curl -s -X PATCH \
    "${API_BASE}/open-apis/drive/v1/files/${DOC_TOKEN}/comments/${cid}?file_type=docx" \
    -H "Authorization: Bearer ${TENANT_TOKEN}" \
    -H "Content-Type: application/json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script issues PATCH requests that resolve comments immediately, with no confirmation prompt, dry-run mode, or explicit warning to the caller. In a collaboration workflow this can silently close active review items, causing loss of visibility and accidental tampering with document review state.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.