T09 · Insecure Skill Coding Practices
- Location
scripts/transfer_owner.py:103- Finding
Unsafe Owner Classification May Transfer Unintended Files
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is for Feishu document ownership transfer, but its bulk mode can change ownership broadly without enough safeguards.
Review before installing. Use dry-run first, prefer explicit per-file tokens or an exact verified --ai-owner filter, and avoid --all unless you have checked every file that will be transferred under the authenticated lark-cli account.
scripts/transfer_owner.py:103Unsafe Owner Classification May Transfer Unintended Files
The skill advertises and instructs use of shell-based capabilities via lark-cli and a Python script, but it does not declare any tool scope restrictions such as permissions or allowed-tools. That creates a mismatch between documented behavior and execution boundaries, increasing the chance an agent can invoke shell commands more broadly than intended during owner-transfer operations on documents.
The trigger phrases include generic terms like 'transfer owner', '文档所有者', and '批量转移', which may match user requests that are broader than this specific high-impact ownership transfer skill. Because the skill performs privileged ownership changes, overly broad activation increases the risk of accidental invocation and unintended transfer of control over documents.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
cmd = ["lark-cli", "api", method, path]
if data:
cmd += ["--data", json.dumps(data)]
result = subprocess.run(cmd, capture_output=True, text=True)
try:
return json.loads(result.stdout)
except json.JSONDecodeError:
This file contains natural-language usage instructions entirely in Chinese, and the rest of the CLI help text also follows that locale. Under the policy rule for language/locale, forcing a specific language without user opt-in or documented justification is a violation.
No suspicious patterns detected.