T09 · Insecure Skill Coding Practices
- Location
skill.md:108- Finding
Configurable API Base Can Exfiltrate Feishu Application Credentials
- Content
View full analysis
Vulnerability Details
File Location:
skill.md, lines 108–112
Vulnerability Type: Unrestricted credential destination controlled through environment configuration
Risk Level: HighVulnerable Code
python import requests, os from dotenv import load_dotenv; load_dotenv() BASE = os.getenv('FEISHU_API_BASE', 'https://open.feishu.cn') r = requests.post(f'{BASE}/open-apis/auth/v3/tenant_access_token/internal', json={'app_id': os.environ['FEISHU_APP_ID'], 'app_secret': os.environ['FEISHU_APP_SECRET']}, timeout=10) token = r.json()['tenant_access_token'] H = {'Authorization': f'Bearer {token}', 'Content-Type': 'application/json'}The corresponding configuration is declared as optional:
yaml optional_env: - FEISHU_API_BASETechnical Analysis
Obtaining a tenant access token from Feishu is necessary for the declared employee-account reconciliation workflow. However, allowing
FEISHU_API_BASEto control the destination of the authentication request is not required for normal operation.The request body contains both
FEISHU_APP_IDandFEISHU_APP_SECRET. No hostname allowlist, URL validation, redirect restriction, or trust-boundary check is applied before transmitting these credentials. An attacker who can modify the process environment or the repository's.envfile can therefore redirect the request to an arbitrary HTTPS endpoint.The same configurable base is subsequently used by the batch user lookup operation, potentially exposing employee email addresses as well as credentials. A timeout limits request duration but does not prevent disclosure.
Attack Path
- An attacker gains the ability to modify the local
.envfile, CI environment variables, deployment configuration, or shell environment. - The attacker sets
FEISHU_API_BASEto a server under their control, such ashttps://attacker.example. - A user invokes the resignation-check workflow.
- The Skill loads the attacker-controlled value an ...[truncated 1166 chars]
- An attacker gains the ability to modify the local
- Remediation
View remediation
Remediation Suggestions
- Remove the
FEISHU_API_BASEoverride and use a fixed official endpoint:
python BASE = 'https://open.feishu.cn'- If alternate endpoints are operationally necessary, enforce an exact allowlist rather than suffix or substring matching:
python from urllib.parse import urlparse ALLOWED_HOSTS = {'open.feishu.cn'} parsed = urlparse(BASE) if parsed.scheme != 'https' or parsed.hostname not in ALLOWED_HOSTS: raise ValueError('Untrusted Feishu API endpoint')- Reject URLs containing user information, unexpected ports, fragments, or non-empty paths before constructing API routes.
- Disable redirects on the credential-bearing request with
allow_redirects=False, and fail closed on any redirect response. - Store the secret in a managed secret store with strict file and process permissions rather than a broadly editable
.envfile. - Ensure logs and exception handlers never include request bodies, authorization headers, access tokens, or application secrets.
- Grant the Feishu application only the minimum read-only contact scopes needed by this workflow.
- Rotate
FEISHU_APP_SECRETimmediately if the environment configuration may already have been modified or exposed.
- Remove the
