T09 · Insecure Skill Coding Practices
- Location
SKILL.md:79- Finding
Hardcoded Feishu Spreadsheet Token and Worksheet Identifiers
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:79-80;references/runtime-notes.md:33-41
Vulnerability Type: Hardcoded workspace resource identifiers and metadata
Risk Level: LowAffected code in
SKILL.md:79-80:markdown For spreadsheet: - `https://bytedance.larkoffice.com/sheets/Bf6qsMV9fhqrD6tPE6TcQhF7nEe`Affected code in
references/runtime-notes.md:33-41:markdown Spreadsheet token: - `Bf6qsMV9fhqrD6tPE6TcQhF7nEe` Final tabs created: - `总览` (`0d138c`, renamed from `Sheet1`) - `Skills` (`GxGIGa`) - `Workflows` (`9dJYiB`) - `Templates` (`pDfjgl`) - `Content` (`ClS7jn`)Technical Analysis
The Skill embeds a real Feishu spreadsheet URL, its document token, and associated worksheet identifiers in distributable documentation. Although the spreadsheet token is not proven to be an authentication credential by itself, it is a direct resource locator and reveals workspace-specific metadata.
An attacker who obtains the Skill package can recover the exact document URL and worksheet structure without independently discovering the resource. Access still depends on Feishu authentication and the document's sharing policy, but the disclosure reduces resource secrecy and may expose the spreadsheet if it is configured for public, organization-wide, or permissive link-based access.
Attack Path
- Obtain or download the Skill package.
- Inspect
SKILL.mdorreferences/runtime-notes.md. - Extract the spreadsheet token
Bf6qsMV9fhqrD6tPE6TcQhF7nEe. - Reconstruct or directly use the disclosed Feishu spreadsheet URL.
- Open the URL through a Feishu account or unauthenticated browser session.
- If the document has permissive sharing settings, access the spreadsheet and its disclosed worksheet structure within the permissions granted by Feishu.
- Use the worksheet IDs to target individual tabs through any interfaces that accept those identifiers.
This p ...[truncated 761 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the real spreadsheet URL, token, worksheet IDs, and workspace-specific metadata from all Skill files.
- Replace them with unambiguously synthetic examples, such as:
markdown https://example.feishu.cn/sheets/REDACTED_EXAMPLE_TOKEN - Remove the identifiers from version-control history and previously distributed artifacts where feasible.
- Review the referenced spreadsheet's Feishu sharing configuration and restrict access to explicitly authorized users.
- Disable public or organization-wide link access unless it is required.
- Recreate or rotate the document's share link if Feishu supports invalidating the disclosed locator.
- Add a publication review or secret-scanning rule that detects Feishu/Lark document URLs and tokens before Skill packages are distributed.
- Keep operational examples generic and store any environment-specific resource identifiers outside distributable documentation.
