Back to skill

Security audit

feishu-bot-ops

Security checks for vulnerabilities and agentic risk

Overview

This Feishu operations skill is legitimate in purpose, but it asks agents to bypass protected configuration controls and make broad access, process, and persistent visibility changes that need human review.

Treat this as a hands-on operator runbook, not something to let an agent execute unattended. Before installing or using it, require approval for any .env/config changes, avoid GATEWAY_ALLOW_ALL_USERS except in tightly controlled temporary diagnostics, pin lark-oapi, stop only verified gateway PIDs gracefully where possible, and back up config before persistent changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:325
Finding

Protected Credential-File Controls Are Explicitly Bypassed

Content
View full analysis
> $HERMES_HOME/.env ``` The surrounding instructions state that the Hermes `write_file` and `patch` tools intentionally refuse to modify `.env`, and then present the terminal command above as a workaround. ### Technical Analysis The Skill directs the Agent to evade an intentional protection on a credential-bearing file by switching to a less-restricted tool. The `.env` file can contain `FEISHU_APP_ID`, `FEISHU_APP_SECRET`, and other unrelated service credentials. Even though the demonstrated command only appends `FEISHU_ALLOW_BOTS`, the operational pattern defeats the platform's protected-file boundary. This behavior is not necessary for Feishu diagnostics. Configuration changes can instead be performed by the user or through a purpose-built configuration interface that validates keys and preserves credential protections. ### Attack Path 1. The Agent loads the Skill while troubleshooting bot-to-bot messaging. 2. The Skill identifies a missing `FEISHU_ALLOW_BOTS` setting. 3. Protected file-editing tools reject modification of `.env`. 4. Following the Skill, the Agent invokes the terminal command instead. 5. The shell writes directly to the protected credential file with the Agent process's filesystem privileges. 6. The persistent configuration change affects subsequent gateway sessions. ### Impact Assessment The instruction grants the Skill an effective path around the platform's protected-file policy. Its direct demonstrated impact is persistent modification of Hermes gateway configuration. More broadly, normalizing this bypass technique weakens safeguards around every secret stored in the same file and could lead to accidental corruption, disclosure, or unauthorized configuration changes. ]]>
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:493
Finding

Recommended Global Gateway Authorization Bypass Violates Least Privilege

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/feishu-gateway-recover.sh:24
Finding

Recovery Script Installs an Unpinned Runtime Dependency

Content
View full analysis
&1 ``` Equivalent unpinned installation instructions also appear in `SKILL.md` at lines 71-75 and 335-344. ### Technical Analysis The recovery operation installs the latest version of `lark-oapi` resolved by the active pip configuration. No exact version, package hash, lock file, or repository restriction is supplied. Consequently, the code installed during a future recovery can differ from the code reviewed when the Skill was published. The package name is consistent throughout the project, and the audit found no evidence that the named package is itself malicious. The vulnerability is the mutable supply-chain trust decision made at runtime. Python package installation may execute build backends or other package-controlled code with the privileges of the user running the recovery script. ### Attack Path 1. An attacker compromises a future package release, distribution account, configured package mirror, or dependency in the resolution chain. 2. The operator invokes the gateway recovery script after rebuilding the environment. 3. `pip` resolves the current mutable package version from the configured index. 4. Package-controlled installation or imported runtime code executes inside the Hermes virtual environment. 5. Malicious code gains the filesystem and network privileges of the recovery-script user. ### Impact Assessment A compromised dependency could modify the Hermes environment, access files readable by the operator, intercept Feishu credentials available to the gateway, alter bot messages, or establish additional malicious behavior. The affected scope is the host account and Hermes installation used to run the script. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:60
Finding

Broad Forced Process Termination Can Kill Unrelated Hermes Workloads

Content
View full analysis
/dev/null; sleep 2 ``` The Skill also recommends the broader command `pkill -9 -f hermes` at line 239. The executable recovery script similarly enumerates processes matching `hermes.*gateway` and sends each one `SIGKILL` at lines 46-50. ### Technical Analysis `pkill -f` matches against full process command lines rather than a verified gateway PID or service identity. The broader documented variant can terminate every matching Hermes process, including independent CLI sessions and other gateway instances. `SIGKILL` prevents graceful shutdown, state flushing, cleanup handlers, and normal lock release. This can cause the same stale-state and lock-file conditions the recovery procedure is intended to repair. The recovery function only needs to stop the specific gateway instance associated with the affected deployment. Process-wide pattern matching exceeds that requirement. ### Attack Path 1. Multiple Hermes sessions or gateway instances are running under the same user. 2. The operator or Agent follows the one-click repair procedure. 3. `pkill -f` matches every process whose command line satisfies the broad pattern. 4. `SIGKILL` immediately terminates all matches without shutdown handling. 5. Unrelated sessions lose in-flight work, while files, logs, or local state may remain incomplete. 6. The script removes lock files and launches a replacement gateway without proving that only the intended instance was affected. ### Impact Assessment The direct impact is denial of service and loss of in-flight Agent work. The scope includes all matching processes accessible to the invoking user. If invoked by a privileged account, the affected scope can include system-wide Hermes services owned by that account. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/feishu-gateway-recover.sh:32
Finding

Connectivity Recovery Silently Disables Operational Visibility

Content
View full analysis
/dev/null || \ hermes config set display.platforms.feishu.tool_progress '"off"' 2>/dev/null || \ hermes config set agent.gateway_notify_interval 0 2>/dev/null || \ ``` The commands disable reasoning display, tool-progress reporting, and long-running gateway notifications. They are executed as part of the default recovery flow rather than as optional display preferences. ### Technical Analysis Restoring the Feishu gateway connection does not require suppressing reasoning output, tool activity, or progress notifications. Combining these changes with recovery alters unrelated persistent configuration without requesting informed consent. Disabling tool-progress and long-running notifications reduces users' ability to observe Agent activity and distinguish a stalled gateway from a lengthy or unexpected tool operation. Suppressing command errors also makes it difficult to determine which settings were successfully changed. This is not evidence of credential exfiltration or a hidden remote-control mechanism, but it is an unsafe operational default that exceeds the minimum changes required for recovery. ### Attack Path 1. A user invokes the script solely to restore Feishu connectivity. 2. Before restarting the gateway, the script changes three persistent display and notification settings. 3. The gateway restarts with reduced operational visibility. 4. Future tool calls and long-running actions provide less feedback to Feishu users. 5. Unexpected, stalled, or unauthorized Agent activity is less likely to be noticed promptly. ### Impact Assessment The affected scope is the Feishu display configuration and the global gateway notification interval for the Hermes ...[truncated 150 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (26)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill recommends force-killing processes and deleting lock files as a 'one-click fix' without requiring confirmation, backup, or warning about service interruption and race conditions. In an agent setting, such instructions can cause avoidable denial of service, data loss, or corruption if executed automatically on the wrong host or at the wrong time.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

Blindly deleting lock files with rm -f can subvert concurrency protections and allow multiple instances or unsafe restarts to proceed. In combination with force-killing processes, this creates a realistic denial-of-service and state-corruption risk if applied incorrectly or automatically.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

bash
# 场景A:多实例/锁文件冲突
pkill -9 -f 'hermes gateway run' 2>/dev/null; sleep 2
rm -f $HERMES_LOCAL_STATE/gateway-locks/feishu-app-id-*.lock
hermes gateway run 2>&1 &
sleep 5 && grep '✓ feishu connected' $HERMES_HOME/logs/gateway.log | tail -1

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The finding is triggered by .env access, and in context the instruction is to modify a sensitive configuration file to disable user restrictions. While merely referencing .env is not always dangerous, here it accompanies a weakening of access control and encourages direct sensitive-file edits.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
# 场景B:鉴权拦截
grep 'Unauthorized' $HERMES_HOME/logs/gateway.log | tail -3
# 如有输出 → .env 加 GATEWAY_ALLOW_ALL_USERS=true,重启

# 场景C:lark-oapi 未安装
<hermes_venv>/bin/python -m ensurepip 2>/dev/null

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

This command sequence removes lock files during restart without proving they are stale, weakening safety controls that prevent concurrent gateway use. If executed in error, it can disrupt service and create inconsistent process state.

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

bash
pkill -9 -f 'hermes gateway'
sleep 2
rm -f $HERMES_LOCAL_STATE/gateway-locks/feishu-app-id-*.lock
hermes gateway run 2>&1 &
sleep 5 && grep '✓ feishu connected' $HERMES_HOME/logs/gateway.log | tail -1

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Although presented as a fix for zombie locks, the unconditional rm -f guidance can remove legitimate locks and invite conflicting instances. The danger is contextual but real in operational automation where the command may be copied without verification.

Content

Scanner excerpt · SKILL.md (reported line 294)May include surrounding context.

修复:

bash
rm -f $HERMES_LOCAL_STATE/gateway-locks/feishu-app-id-*.lock

多实例冲突

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

This repeats a destructive pattern of forceful process termination followed by unconditional lock-file deletion to recover service. In an agent skill, repeated presentation of these commands as standard remediation increases the likelihood of unsafe automated execution and avoidable outage.

Content

Scanner excerpt · SKILL.md (reported line 309)May include surrounding context.

修复三步走:

bash
pkill -9 -f 'hermes gateway run'; sleep 2
rm -f $HERMES_LOCAL_STATE/gateway-locks/feishu-app-id-*.lock
hermes gateway run 2>&1 &
sleep 5 && grep '✓ feishu connected' $HERMES_HOME/logs/gateway.log | tail -1

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

This section explicitly discusses writing to a protected credential file despite tool restrictions. Even without showing a secret value, it promotes unsafe direct handling of a secret-bearing file and defeats the platform's intended guardrails.

Content

Scanner excerpt · SKILL.md (reported line 324)May include surrounding context.

md
**预防**:不要同时开多个 hermes CLI 会话。用完 `/exit` 退出,别直接关终端。

### .env 写入保护

Hermes 的 `write_file` 和 `patch` 工具拒绝写入 `.env`(受保护的凭据文件)。变通方案:用 `terminal` 直接 shell 写入:

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The explicit shell append into $HERMES_HOME/.env instructs modification of a protected credential-bearing file outside the normal safety controls. This can introduce insecure settings, duplicate entries, accidental leakage, and unauthorized persistence changes.

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

Hermes 的 write_file 和 patch 工具拒绝写入 .env(受保护的凭据文件)。变通方案:用 terminal 直接 shell 写入:

bash
printf 'FEISHU_ALLOW_BOTS=mentions\n' >> $HERMES_HOME/.env

修改后必须重启 gateway 生效。

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
# 用途:容器重装 / venv 重建后恢复飞书 bot 连接 + 飞书端显示优化
# 用法:bash scripts/feishu-gateway-recover.sh
#
# 使用前请确认环境变量已在 ~/.hermes/.env 中正确配置:
#   FEISHU_APP_ID, FEISHU_APP_SECRET

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
# 用途:容器重装 / venv 重建后恢复飞书 bot 连接 + 飞书端显示优化
# 用法:bash scripts/feishu-gateway-recover.sh
#
# 使用前请确认环境变量已在 ~/.hermes/.env 中正确配置:
#   FEISHU_APP_ID, FEISHU_APP_SECRET

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/at-mention-code-fix.md (reported line 55)May include surrounding context.

md
# 用途:容器重装 / venv 重建后恢复飞书 bot 连接 + 飞书端显示优化
# 用法:bash scripts/feishu-gateway-recover.sh
#
# 使用前请确认环境变量已在 ~/.hermes/.env 中正确配置:
#   FEISHU_APP_ID, FEISHU_APP_SECRET

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/feishu-gateway-recover.sh (reported line 6)May include surrounding context.

sh
# 用途:容器重装 / venv 重建后恢复飞书 bot 连接 + 飞书端显示优化
# 用法:bash scripts/feishu-gateway-recover.sh
#
# 使用前请确认环境变量已在 ~/.hermes/.env 中正确配置:
#   FEISHU_APP_ID, FEISHU_APP_SECRET

set -e

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/feishu-gateway-recover.sh (reported line 51)May include surrounding context.

sh
kill -9 "$pid" 2>/dev/null && echo "  killed PID $pid"
done
if ls "$LOCK_DIR"/feishu-app-id-*.lock 2>/dev/null; then
    rm -f "$LOCK_DIR"/feishu-app-id-*.lock
    echo "  ✓ 锁文件已清理"
else
    echo "  ✓ 无残留锁文件"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/feishu-gateway-recover.sh (reported line 61)May include surrounding context.

sh
echo ""
echo "=== 4/5 启动 Gateway ==="
set -a
source "$HERMES_HOME/.env" 2>/dev/null || true
set +a

hermes gateway run 2>&1 &

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 21)May include surrounding context.

bash
# 克隆到 skills 目录
mkdir -p ~/.hermes/skills/feishu/
git clone <repo-url> ~/.hermes/skills/feishu/feishu-bot-ops/

# 或手动复制 SKILL.md + scripts/ 过去

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language instructions throughout the skill are exclusively in Chinese, and the file does not state that the skill is China-region-specific or offer an alternative language. If organizational policy requires not forcing a specific language without opt-in, this is a documentation-level locale policy issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction says the skill should activate when a user says '飞书不能用了 / 没反应', which is a broad natural-language complaint rather than a specific command or tightly scoped trigger. Without explicit boundaries or negative examples, this could overlap with everyday troubleshooting chat and cause unintended invocation.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The recommendation to set GATEWAY_ALLOW_ALL_USERS=true disables a gateway-level access-control check in order to make messages flow. This weakens the trust boundary for the bot and can expose it to unsolicited or unauthorized interactions, especially dangerous in group-chat or enterprise environments.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guidance to disable the @mention requirement expands the bot's intake from explicit summons to all group messages. That broadens passive collection and processing of conversations, increasing privacy exposure and the chance the bot acts on unintended content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly advises bypassing built-in protections on the sensitive .env file by writing to it through a shell. This undermines a security boundary intended to prevent accidental or unauthorized credential/config changes, and can normalize unsafe handling of secrets in an agent workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Appending directly to .env without validation or warnings can corrupt configuration, create duplicate keys, or expose secrets through shell history and logs. Because .env is a protected credential-bearing file, encouraging ad hoc writes increases both operational and security risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The content instructs users to bypass protection around a credentials file, which is effectively advice to defeat a safety mechanism guarding sensitive configuration. That increases the chance of unauthorized secret changes, persistence of insecure settings, and accidental credential exposure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 420)May include surrounding context.

发送测试卡片

bash
curl -s -X POST 'https://open.feishu.cn/open-apis/im/v1/messages?receive_id_type=chat_id' \
  -H "Authorization: Bearer $TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

发送 @某人 测试消息后,用飞书 API 反查:

bash
TOKEN=$(curl -s -X POST 'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal' \
  -H 'Content-Type: application/json' \
  -d "{\"app_id\":\"$FEISHU_APP_ID\",\"app_secret\":\"$FEISHU_APP_SECRET\"}" | \
  grep -oP '"tenant_access_token":"\K[^"]+')

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 378)May include surrounding context.

发送 @某人 测试消息后,用飞书 API 反查:

bash
TOKEN=$(curl -s -X POST 'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal' \
  -H 'Content-Type: application/json' \
  -d "{\"app_id\":\"$FEISHU_APP_ID\",\"app_secret\":\"$FEISHU_APP_SECRET\"}" | \
  grep -oP '"tenant_access_token":"\K[^"]+')

Static analysis

No suspicious patterns detected.