T05 · Unauthorized Access and Privilege Escalation
- Location
references/pipeline-detail.md:461- Finding
Default Feishu Cloud Upload May Disclose Confidential Transcript Content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a disclosed Chinese WeChat article-writing workflow, but it defaults to copying and uploading transcript-derived output to Feishu cloud storage under the user's account without clear per-run consent.
Review before installing if you may process confidential interviews, meeting notes, personal data, or unpublished business material. Use it only if you want a Chinese WeChat-style workflow and are comfortable with web research, local output files, Desktop copies, and possible Feishu cloud upload; explicitly decline Feishu upload for sensitive work and verify sourced claims, especially preprints.
references/pipeline-detail.md:461Default Feishu Cloud Upload May Disclose Confidential Transcript Content
The skill is described as a transcript-to-article workflow, but it also performs local file duplication to the Desktop and uploads output to Feishu cloud storage. Those actions materially expand the skill’s data-handling scope beyond content transformation into persistence and third-party exfiltration, which is dangerous when transcripts may contain confidential interview material or personal data.
The document instructs the agent to run shell/CLI commands for file copying and lark-cli upload, granting capabilities that are unnecessary for summarization or rewriting. This broadens the attack surface from text processing to host-side file operations and external service interaction, enabling unintended data movement if the skill is invoked on sensitive content.
The manifest description and task section specify transforming transcripts into WeChat long-form articles in Chinese, and the entire output format is tailored to a Chinese公众号 format. There is no indication that users may choose another language or locale, so the skill imposes a language/locale constraint without opt-in.
The document is entirely a prescriptive writing policy in Chinese, with multiple absolute directives such as "永远", "绝对禁用", and style constraints that require one specific linguistic register. There is no user opt-in, language/locale choice, or documented justification that this restriction is region-specific, which matches the policy concern for forced language or locale behavior.
This markdown file is natural-language guidance, and its title and content enforce Chinese as the operating language without any opt-in or statement that the skill is region- or language-specific. Under the policy, forcing a specific language without user choice is a locale/language policy violation.
The file title and all operational instructions are written exclusively in Chinese, and the prescribed output format uses Chinese labels, which indicates a fixed language expectation. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly justified, which this file does not do.
The workflow includes language detection but gives no option for preserving or selecting the user's preferred output language, and all natural-language instructions are framed for Chinese-language operation. This can amount to forcing a specific language/locale without explicit user opt-in.
The workflow requires 100% incorporation of all supplemental information into the final article, which pressures the agent to include every user-provided detail regardless of sensitivity or relevance. In a writing pipeline, that increases the risk of natural-language leakage of confidential notes, personal data, or proprietary facts that should be filtered, minimized, or omitted.
The workflow duplicates files locally and uploads them to a third-party cloud service without requiring a user-facing disclosure about additional copies, retention, or external transmission. Even if the actions are expected operationally, the lack of transparency and informed consent creates privacy and compliance risk for sensitive transcripts and derived articles.
Copying generated content to a user Desktop is a local persistence action that is not necessary to perform transcript analysis or article drafting. It creates extra plaintext copies in a highly exposed location, increasing the chance of accidental disclosure through shared machines, sync clients, backup systems, or shoulder-surfing.
Uploading the final article to Feishu can transmit user-derived content to an external service without any required sensitivity screening of the transcript, quotes, or supplemental data. Because the skill handles interviews and source material that may contain confidential business discussions or personal information, automatic cloud transmission materially raises data leakage risk.
The document title and all checklist instructions are written exclusively in Chinese, which establishes a single required language for operating the skill. There is no indication that users may choose another language or opt in to this locale, so this is a natural-language locale policy issue.
This markdown file contains user-facing operational instructions exclusively in Chinese, and it does not indicate that the language is optional or region-specific. Under the policy rule for natural-language locale constraints, forcing a specific language without user opt-in is a reportable issue.
The entire skill specification, templates, examples, and output format are written exclusively in Chinese, with no indication that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly justified, which is not stated here.
The entire routing guide is written as a Chinese-only workflow and repeatedly prioritizes Chinese platforms and Chinese-language query patterns, but it does not state that this locale restriction is optional or region-specific. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.
The file labels arXiv API results as '同行评审/官方预印本' and Tier 1, which materially overstates their reliability because arXiv hosts preprints that are not necessarily peer reviewed. This can cause the agent to treat unvetted claims as authoritative facts, increasing the risk of misinformation in generated articles.
The manifest describes a workflow for extracting interview content and turning it into a long-form WeChat article with search supplementation. Lines L093-L094 document mx-zixuan for watchlist management and mx-moni for simulated trading, which are finance account/transaction-style capabilities not justified by the skill’s stated content-processing purpose.
The instruction that supplemental information '绝不留空' and should be preserved even as '[AI推断]' encourages the agent to surface unsupported generated content rather than maintaining evidentiary integrity. In a workflow meant to transform interviews into deep long-form articles, this is especially dangerous because readers may infer that all inserted details were researched and sourced.
The fallback flow instructs the agent to use 'Agent 已知信息填充' and '[AI推断](绝不留空)' when no evidence is found. Even with internal labels, this normalizes fabrication as output completion behavior and creates a strong risk that unverifiable or false claims will be presented to end users in a polished article.
The file instructs that original quotations must use Chinese corner quotes 「」, which imposes a specific locale/style convention in mandatory language. Because the guidance does not present this as optional or limited to Chinese-language公众号 output only, it reads as a forced locale requirement.
No suspicious patterns detected.