Back to skill

Security audit

Feishu Whiteboard Extract

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it needs Review because it uses Feishu app credentials to retrieve and save whiteboard data, includes an under-disclosed raw node exporter, and has unsafe file and dependency handling.

Install only if you trust the publisher with Feishu app credentials and whiteboard contents. Treat this as a network-enabled Feishu data export tool, not just a file-token extractor; avoid using export_nodes_raw.js unless you explicitly need all board node data, constrain output paths, and regenerate/update dependencies from an HTTPS trusted registry before operational use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
download_media.js:13
Finding

Unvalidated media token can escape the intended download directory

Content
View full analysis
{ const req = https.request({ hostname: 'open.feishu.cn', // 关键: medias endpoint,不是 files endpoint path: `/open-apis/drive/v1/medias/${fileToken}/download`, method: 'GET', headers: { 'Authorization': `Bearer ${token}` } }, res => { if (res.statusCode !== 200) { let errData = ''; res.on('data', c => errData += c); res.on('end', () => reject(new Error(`HTTP ${res.statusCode}: ${errData}`))); return; } // Detect extension from content-type const ct = res.headers['content-type'] || ''; let ext = '.png'; if (ct.includes('jpeg') || ct.includes('jpg')) ext = '.jpg'; else if (ct.includes('gif')) ext = '.gif'; else if (ct.includes('webp')) ext = '.webp'; const outPath = finalPath || path.join( os.homedir(), '.openclaw', 'workspace', 'input', 'feishu_downloads', `${fileToken}${ext}` ); fs.mkdirSync(path.dirname(outPath), { recursive: true }); const ws = fs.createWriteStream(outPath); res.pipe(ws); ws.on('finish', () => resolve(outPath)); ws.on('error', reject); }); req.on('error', reject); req.end(); }); } async function main() { try { const token = await getTenantToken(); const outputDir = path.join(os.homedir(), '.openclaw', 'workspace', 'input', 'feishu_downloads'); fs.mkdir ...[truncated 2108 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
export_nodes_raw.js:60
Finding

Undocumented raw exporter exposes all accessible whiteboard node data

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package-lock.json:14
Finding

Dependency lockfile retrieves packages from a plaintext HTTP mirror

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (26)

Known Vulnerable Dependency: protobufjs==7.5.4 — 12 advisory(ies): CVE-2026-44294 (protobuf.js: Denial of service from crafted field names in generated code); CVE-2026-44293 (protobuf.js: Code injection through bytes field defaults in generated toObject c); CVE-2026-44289 (protobuf.js: Denial of service through unbounded protobuf recursion) +9 more

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

protobufjs 7.5.4 is flagged with multiple serious advisories including code injection and denial-of-service conditions. Since the Lark/Feishu SDK depends on protobufjs and may parse structured remote data, a vulnerable protobuf implementation in an integration skill increases the risk of process crash, resource exhaustion, or unsafe code-generation paths if hostile input is ever reachable.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented workflow indicates access to broader whiteboard content and even whole-board export, not just extraction of image-node tokens. In document-processing contexts, that broader-than-declared collection can cause overreach, pulling sensitive non-image content or complete visual context that users did not intend to expose through a narrowly described extraction skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented workflow indicates access to broader whiteboard content and even whole-board export, not just extraction of image-node tokens. In document-processing contexts, that broader-than-declared collection can cause overreach, pulling sensitive non-image content or complete visual context that users did not intend to expose through a narrowly described extraction skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented workflow indicates access to broader whiteboard content and even whole-board export, not just extraction of image-node tokens. In document-processing contexts, that broader-than-declared collection can cause overreach, pulling sensitive non-image content or complete visual context that users did not intend to expose through a narrowly described extraction skill.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
2) 第二部分:整板全图导出(`export_board_svg.js`,用于复核与归档)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code materially exceeds the declared skill purpose. Instead of only extracting whiteboard image file_token values, it obtains a tenant access token, downloads media content from Feishu, and writes the files to local disk, creating a capability for data exfiltration and persistent storage of sensitive content. In the context of a narrowly described extraction skill, this mismatch is especially dangerous because users and reviewers may not expect content retrieval or local retention.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation materially differs from the declared skill purpose: instead of extracting image-node file_token values, it authenticates to Feishu and downloads a full whiteboard rendering. That expands data access from targeted identifiers to complete board contents, which can expose unrelated sensitive text, diagrams, and embedded information and violates least-privilege expectations for the skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script’s implemented behavior materially exceeds the stated skill purpose: instead of extracting only image-node file_token values, it retrieves and prints every whiteboard node in raw form. That increases data exposure by disclosing potentially sensitive board structure and content metadata unrelated to the requested task, violating least-privilege and creating a stealthy over-collection risk in an agent skill context.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.5 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
94% confidence
Finding

axios 1.13.5 is flagged with multiple advisories including SSRF/proxy bypass and prototype-pollution-related MITM or credential exposure scenarios. This skill talks to external Feishu/Lark APIs, so an HTTP client flaw is more dangerous here because the skill likely handles access tokens and makes outbound requests based on runtime configuration.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
80% confidence
Finding

form-data 4.0.5 is flagged for CRLF injection via multipart field names and filenames. This skill appears focused on extracting whiteboard image file tokens rather than uploading arbitrary multipart content, so practical exploitability may be limited, but the vulnerable library remains present and could become reachable through SDK features or future code changes.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
88% confidence
Finding

ws 8.19.0 is flagged for memory disclosure and memory exhaustion issues. If the Feishu SDK or future skill functionality uses WebSocket connections, a malicious peer could trigger resource exhaustion or expose sensitive process memory, which is especially concerning in a token-handling integration environment.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documentation describes commands that use Node.js scripts to access Feishu APIs, download media, export whiteboards, and read credentials from environment or local config, but it declares no explicit tool scope or permission boundaries. In an agent environment, missing scope declarations can let a seemingly narrow skill gain network and credential access without clear user visibility or enforcement.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script reads local Feishu app credentials and exchanges them for a tenant access token even though the advertised function is token extraction. Accessing secrets from a local config broadens trust boundaries and enables authenticated access to tenant resources beyond what a user would reasonably expect from this skill description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script silently reads sensitive local credentials from ~/.openclaw/openclaw.json without any user-facing disclosure. Hidden secret access is dangerous because it undermines informed consent and can let a seemingly harmless skill leverage existing local trust material to access external systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code makes authenticated outbound requests to Feishu APIs using locally sourced credentials, but gives no user-facing warning that identifiers and authentication material are being used to contact a remote service. This is risky because a user may believe the skill is only doing local token extraction, while it is actually performing network actions against tenant data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · export_board_svg.js (reported line 96)May include surrounding context.

js
}

async function getTenantAccessToken(appId, appSecret) {
    const res = await fetch('https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal', {
        method: 'POST',
        headers: { 'Content-Type': 'application/json; charset=utf-8' },
        body: JSON.stringify({ app_id: appId, app_secret: appSecret }),

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill writes downloaded whiteboard content to an arbitrary user-supplied path even though its stated function is only to extract identifiers. This unnecessary file-write capability increases the blast radius by persisting sensitive board data locally, potentially into unexpected locations, and creates opportunities for accidental disclosure or overwriting of files in the agent environment.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The header comment explicitly states the file exports all raw whiteboard nodes, which contradicts the skill description claiming only image file_token extraction. In a security review, this mismatch is significant because it signals undeclared broader collection behavior and increases the likelihood that operators or downstream agents will trust the manifest while the code performs more invasive data access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The stated purpose is whiteboard image-token extraction, but the code additionally reads secrets from process environment and a user home-directory config file. While authentication to Feishu is expected, harvesting credentials from a local shared config store is a broader local-data access capability that is not disclosed in the manifest description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script silently loads local or environment credentials and uses them to query remote Feishu APIs, then prints the retrieved board data, without any user-facing disclosure of credential usage or the breadth of transmitted and returned data. In an agent skill setting, that lack of notice is risky because users may invoke a seemingly narrow extraction tool while unknowingly authorizing broader access and export of board contents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The lockfile pins package tarballs to plain HTTP mirror URLs, which allows a network attacker or compromised mirror path to tamper with dependency downloads in transit. Although integrity hashes provide some protection, using unauthenticated transport still weakens supply-chain trust and can enable downgrade, availability, or misconfiguration risks in some install workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code emits a user-facing error string that includes Chinese text (请确认白板已分享给 bot/app 且应用具备白板访问权限。) without any indication that the user opted into that locale or that the tool is region-specific. Under the natural-language policy rule, forcing a specific language in messages without opt-in is a locale-policy concern.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @protobufjs/utf8==1.1.0 — 1 advisory(ies): CVE-2026-44288 (protobufjs has overlong UTF-8 decoding)

Low
Category
Supply Chain
Confidence
76% confidence
Finding

The lockfile includes @protobufjs/utf8 1.1.0, which is reported as affected by an overlong UTF-8 decoding issue. In this skill, the package is only a transitive dependency, so exploitability depends on whether untrusted protobuf/UTF-8 inputs are processed, but keeping a known vulnerable parser in the tree is still risky.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: follow-redirects==1.15.11 — 1 advisory(ies): CVE-2026-40895 (follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Ta)

Low
Category
Supply Chain
Confidence
83% confidence
Finding

follow-redirects 1.15.11 is reported to leak custom authentication headers across cross-domain redirects. Because this skill likely uses API credentials or bearer tokens when calling Feishu APIs, an unexpected redirect could disclose sensitive headers to another domain if redirect behavior is not tightly controlled.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: qs==6.15.0 — 3 advisory(ies): CVE-2026-82417 (qs: Denial of Service via Attacker Controlled isBuffer); CVE-2026-8723 (qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/u); CVE-2026-82562 (qs array-limit bypass via bracket-key comma parsing)

Low
Category
Supply Chain
Confidence
79% confidence
Finding

qs 6.15.0 is reported as affected by several denial-of-service issues in querystring parsing/stringifying edge cases. In this skill, qs is a transitive helper library, so impact is likely limited unless attacker-controlled objects or query parameters are passed through the HTTP client stack at scale.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
export_board_svg.js:31