Back to skill

Security audit

Feishu Owner Transfer

Security checks for vulnerabilities and agentic risk

Overview

This skill is for Feishu document ownership transfer, but its bulk mode can change ownership broadly without enough safeguards.

Review before installing. Use dry-run first, prefer explicit per-file tokens or an exact verified --ai-owner filter, and avoid --all unless you have checked every file that will be transferred under the authenticated lark-cli account.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/transfer_owner.py:103
Finding

Unsafe Owner Classification May Transfer Unintended Files

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises and instructs use of shell-based capabilities via lark-cli and a Python script, but it does not declare any tool scope restrictions such as permissions or allowed-tools. That creates a mismatch between documented behavior and execution boundaries, increasing the chance an agent can invoke shell commands more broadly than intended during owner-transfer operations on documents.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrases include generic terms like 'transfer owner', '文档所有者', and '批量转移', which may match user requests that are broader than this specific high-impact ownership transfer skill. Because the skill performs privileged ownership changes, overly broad activation increases the risk of accidental invocation and unintended transfer of control over documents.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/transfer_owner.py (reported line 19)May include surrounding context.

python
cmd = ["lark-cli", "api", method, path]
    if data:
        cmd += ["--data", json.dumps(data)]
    result = subprocess.run(cmd, capture_output=True, text=True)
    try:
        return json.loads(result.stdout)
    except json.JSONDecodeError:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains natural-language usage instructions entirely in Chinese, and the rest of the CLI help text also follows that locale. Under the policy rule for language/locale, forcing a specific language without user opt-in or documented justification is a violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.