Back to skill

Security audit

Resignation Check

Security checks for vulnerabilities and agentic risk

Overview

This skill performs a legitimate employee offboarding task, but it combines account-deletion authority, multiple enterprise secrets, mutable external code, and a configurable credential destination in a way users should review carefully before installing.

Install only if you trust and pin the external office365-tools repository and dependencies, restrict or remove `FEISHU_API_BASE`, isolate credentials by provider and workflow stage, use least-privilege app permissions where possible, and require a separate explicit deletion approval with the exact account list. Treat generated reports and `/tmp` deletion logs as sensitive identity records.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
skill.md:108
Finding

Configurable API Base Can Exfiltrate Feishu Application Credentials

Content
View full analysis

Vulnerability Details

File Location: skill.md, lines 108–112
Vulnerability Type: Unrestricted credential destination controlled through environment configuration
Risk Level: High

Vulnerable Code

python
import requests, os
from dotenv import load_dotenv; load_dotenv()
BASE = os.getenv('FEISHU_API_BASE', 'https://open.feishu.cn')
r = requests.post(f'{BASE}/open-apis/auth/v3/tenant_access_token/internal',
    json={'app_id': os.environ['FEISHU_APP_ID'],
          'app_secret': os.environ['FEISHU_APP_SECRET']}, timeout=10)
token = r.json()['tenant_access_token']
H = {'Authorization': f'Bearer {token}', 'Content-Type': 'application/json'}

The corresponding configuration is declared as optional:

yaml
optional_env:
  - FEISHU_API_BASE

Technical Analysis

Obtaining a tenant access token from Feishu is necessary for the declared employee-account reconciliation workflow. However, allowing FEISHU_API_BASE to control the destination of the authentication request is not required for normal operation.

The request body contains both FEISHU_APP_ID and FEISHU_APP_SECRET. No hostname allowlist, URL validation, redirect restriction, or trust-boundary check is applied before transmitting these credentials. An attacker who can modify the process environment or the repository's .env file can therefore redirect the request to an arbitrary HTTPS endpoint.

The same configurable base is subsequently used by the batch user lookup operation, potentially exposing employee email addresses as well as credentials. A timeout limits request duration but does not prevent disclosure.

Attack Path

  1. An attacker gains the ability to modify the local .env file, CI environment variables, deployment configuration, or shell environment.
  2. The attacker sets FEISHU_API_BASE to a server under their control, such as https://attacker.example.
  3. A user invokes the resignation-check workflow.
  4. The Skill loads the attacker-controlled value an ...[truncated 1166 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the FEISHU_API_BASE override and use a fixed official endpoint:
python
BASE = 'https://open.feishu.cn'
  1. If alternate endpoints are operationally necessary, enforce an exact allowlist rather than suffix or substring matching:
python
from urllib.parse import urlparse

ALLOWED_HOSTS = {'open.feishu.cn'}
parsed = urlparse(BASE)

if parsed.scheme != 'https' or parsed.hostname not in ALLOWED_HOSTS:
    raise ValueError('Untrusted Feishu API endpoint')
  1. Reject URLs containing user information, unexpected ports, fragments, or non-empty paths before constructing API routes.
  2. Disable redirects on the credential-bearing request with allow_redirects=False, and fail closed on any redirect response.
  3. Store the secret in a managed secret store with strict file and process permissions rather than a broadly editable .env file.
  4. Ensure logs and exception handlers never include request bodies, authorization headers, access tokens, or application secrets.
  5. Grant the Feishu application only the minimum read-only contact scopes needed by this workflow.
  6. Rotate FEISHU_APP_SECRET immediately if the environment configuration may already have been modified or exposed.

T08 · Insecure Dependencies

Warning
Location
skill.md:27
Finding

Unpinned External Repository and Python Dependencies Create a Supply-Chain Execution Risk

Content
View full analysis

Vulnerability Details

File Location: skill.md, lines 27–33
Vulnerability Type: Installation and execution of mutable, unpinned third-party code
Risk Level: Medium

Vulnerable Code

markdown
## Project Repo

🔗 **https://github.com/eggyrooch-blip/office365-tools**

本 skill 依赖上面这个 Python CLI。Agent 执行前**先确认 repo 已 clone 到本地**;遇到任何不确定的实现细节(CLI 子命令签名、`.env` 变量名、API 返回字段)**优先去仓库查 `README.md` / `CLAUDE.md` / `docs/`**,不要凭本 skill 描述臆断。仓库是 single source of truth。

## Prerequisites(必读)

1. `git clone https://github.com/eggyrooch-blip/office365-tools && cd office365-tools && pip install -r requirements.txt`

The Skill later executes functionality imported from or provided by that repository:

python
from app.services.provider_factory import get_provider
p = get_provider('office365')
users = p.graph_client.get_users(select='userPrincipalName,displayName,accountEnabled')

Technical Analysis

The installation instructions clone the current default branch of an external repository without pinning a reviewed commit or verifying its integrity. They then install packages from the repository's mutable requirements.txt without requiring locked versions or package hashes.

Consequently, the code executed by the effective Skill can change after this Skill has been reviewed. Compromise of the repository, its maintainer account, a referenced package, or a package-distribution account could introduce arbitrary code into installation, import, or CLI execution paths.

This risk is amplified by the sensitivity of the intended runtime environment. The external code can run in a process that has access to Office 365, Adobe, SMTP, and Feishu credentials. The Skill also instructs users to assign powerful Office 365 permissions, including User.ReadWrite.All and LicenseAssignment.ReadWrite.All.

The audit found no evidence that the referenced repository or its dependencies are currently malicious. The vulnerability is the absence of re ...[truncated 1703 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the external repository to a specific reviewed commit rather than cloning a mutable default branch:
bash
git clone https://github.com/eggyrooch-blip/office365-tools
cd office365-tools
git checkout --detach <reviewed-commit-sha>
  1. Verify the checked-out commit against an expected SHA before installation or execution.
  2. Prefer signed release tags or verified commits and document the expected signer identity.
  3. Replace mutable dependency specifications with a reviewed lock file containing exact versions and cryptographic hashes.
  4. Install Python packages with hash enforcement:
bash
python -m pip install --require-hashes -r requirements.lock
  1. Review all transitive dependencies and reject direct URL, VCS, editable, or unexpected package-index dependencies unless explicitly approved and integrity-pinned.
  2. Install and run the CLI in an isolated virtual environment or container under a non-privileged operating-system account.
  3. Do not expose every service credential to the same process. Provide only the credentials needed for the selected provider and workflow stage.
  4. Separate read-only reconciliation from deletion operations so inventory code does not automatically receive write-capable credentials.
  5. Re-audit the pinned external repository and lock file whenever either pinned version is updated.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill requires multiple high-privilege credentials, including Office 365 permissions such as User.ReadWrite.All and LicenseAssignment.ReadWrite.All, Adobe server-to-server credentials, and Feishu app secrets. Consolidating these secrets in one workflow creates a powerful cross-system blast radius: misuse or compromise could enumerate users, modify identities, assign or remove licenses, and delete accounts across several enterprise platforms.

Content

Scanner excerpt · skill.md (reported line 39)May include surrounding context.

  1. Office 365 Entra App 已授予 User.ReadWrite.All / LicenseAssignment.ReadWrite.All 管理员同意
  2. Adobe Developer Console 已建 OAuth Server-to-Server credential 并绑定 User Management API

.env 模板(复制到 office-usertools/.env 后按实际填写)

env
# --------- Office 365(世纪互联) ---------

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises broad trigger phrases such as '离职检查', '清户', and similar everyday administrative terms for a workflow that can culminate in account deletion. Ambiguous activation raises the risk of accidental invocation of a high-impact operation, especially in conversational environments where short phrases may appear in planning or discussion rather than as intentional execution commands.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill requests and documents SMTP credentials and enables outbound email as part of a workflow primarily framed as Feishu-based resignation checking. This broadens the privilege and data-exfiltration surface unnecessarily: a compromised or misused skill could send unauthorized emails, leak account status, or be repurposed for phishing from a trusted mailbox.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The mandatory trigger section lacks robust constraints and maps common phrases directly to the full workflow, including destructive follow-on behavior. In context, this is more dangerous because the skill handles high-privilege credentials and can delete Office 365 and Adobe accounts, so mistaken invocation could produce irreversible identity-management impact.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 109)May include surrounding context.

md
import requests, os
from dotenv import load_dotenv; load_dotenv()
BASE = os.getenv('FEISHU_API_BASE', 'https://open.feishu.cn')
r = requests.post(f'{BASE}/open-apis/auth/v3/tenant_access_token/internal',
    json={'app_id': os.environ['FEISHU_APP_ID'],
          'app_secret': os.environ['FEISHU_APP_SECRET']}, timeout=10)
token = r.json()['tenant_access_token']

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

The skill transmits batches of employee email addresses to an external service for status reconciliation. Although this is part of the intended function, it still creates a real data-exposure risk because account inventories are sensitive corporate identity data, and the destination can be changed through FEISHU_API_BASE, increasing the possibility of exfiltration to an attacker-controlled endpoint.

Content

Scanner excerpt · skill.md (reported line 123)May include surrounding context.

md
out = {}
    for i in range(0, len(emails), 50):
        batch = emails[i:i+50]
        r = requests.post(f'{BASE}/open-apis/contact/v3/users/batch_get_id',
            headers=H, params={'user_id_type':'user_id'},
            json={'emails': batch}, timeout=15)
        for item in r.json().get('data', {}).get('user_list', []):

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description frames the skill as checking Office 365/Adobe users against Feishu and then interactively confirming deletion of suspected departed accounts. However, the documented deletion step explicitly says Office 365 deletion will "自动发通知邮件", adding an outbound email action that is not disclosed in the manifest description and goes beyond simple checking and deletion confirmation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
67% confidence
Finding

Line L099 says the skill does not depend on lark-cli, suggesting a self-contained direct-API approach for Feishu. But nearby documentation makes the external office-usertools CLI repository the authoritative implementation source and later instructs execution via CLI delete commands, creating mixed guidance about whether behavior is API-driven versus CLI-dependent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.