Back to skill

Security audit

feishu-sheet-tabs

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent purpose, but it edits live Feishu spreadsheets through an authenticated browser session and includes a real-looking spreadsheet locator without enough guardrails.

Review before installing. This skill should only be used on a specific spreadsheet URL you provide, after the agent states the exact tabs it will create or rename and you approve the changes. Avoid using it with unrelated Feishu tabs open, and replace the embedded example spreadsheet token with a clearly fake placeholder before publishing or sharing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:79
Finding

Hardcoded Feishu Spreadsheet Token and Worksheet Identifiers

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:79-80; references/runtime-notes.md:33-41
Vulnerability Type: Hardcoded workspace resource identifiers and metadata
Risk Level: Low

Affected code in SKILL.md:79-80:

markdown
For spreadsheet:
- `https://bytedance.larkoffice.com/sheets/Bf6qsMV9fhqrD6tPE6TcQhF7nEe`

Affected code in references/runtime-notes.md:33-41:

markdown
Spreadsheet token:
- `Bf6qsMV9fhqrD6tPE6TcQhF7nEe`

Final tabs created:
- `总览` (`0d138c`, renamed from `Sheet1`)
- `Skills` (`GxGIGa`)
- `Workflows` (`9dJYiB`)
- `Templates` (`pDfjgl`)
- `Content` (`ClS7jn`)

Technical Analysis

The Skill embeds a real Feishu spreadsheet URL, its document token, and associated worksheet identifiers in distributable documentation. Although the spreadsheet token is not proven to be an authentication credential by itself, it is a direct resource locator and reveals workspace-specific metadata.

An attacker who obtains the Skill package can recover the exact document URL and worksheet structure without independently discovering the resource. Access still depends on Feishu authentication and the document's sharing policy, but the disclosure reduces resource secrecy and may expose the spreadsheet if it is configured for public, organization-wide, or permissive link-based access.

Attack Path

  1. Obtain or download the Skill package.
  2. Inspect SKILL.md or references/runtime-notes.md.
  3. Extract the spreadsheet token Bf6qsMV9fhqrD6tPE6TcQhF7nEe.
  4. Reconstruct or directly use the disclosed Feishu spreadsheet URL.
  5. Open the URL through a Feishu account or unauthenticated browser session.
  6. If the document has permissive sharing settings, access the spreadsheet and its disclosed worksheet structure within the permissions granted by Feishu.
  7. Use the worksheet IDs to target individual tabs through any interfaces that accept those identifiers.

This p ...[truncated 761 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the real spreadsheet URL, token, worksheet IDs, and workspace-specific metadata from all Skill files.
  2. Replace them with unambiguously synthetic examples, such as:
    markdown
    https://example.feishu.cn/sheets/REDACTED_EXAMPLE_TOKEN
    
  3. Remove the identifiers from version-control history and previously distributed artifacts where feasible.
  4. Review the referenced spreadsheet's Feishu sharing configuration and restrict access to explicitly authorized users.
  5. Disable public or organization-wide link access unless it is required.
  6. Recreate or rotate the document's share link if Feishu supports invalidating the disclosed locator.
  7. Add a publication review or secret-scanning rule that detects Feishu/Lark document URLs and tokens before Skill packages are distributed.
  8. Keep operational examples generic and store any environment-specific resource identifiers outside distributable documentation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to mutate an existing Feishu spreadsheet through browser automation but does not require an explicit user-facing warning or confirmation before making changes. Because this operates on an existing document and bypasses the normal API path, it increases the risk of unintended modification to user data, especially if the wrong spreadsheet is open or the user did not realize browser automation would perform live edits.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill prefers using the user's real Chrome Feishu session via Browser Relay but does not warn about the privacy and session implications of acting inside a live authenticated browser. This can expose unrelated documents, permit unintended actions under the user's identity, and blur consent boundaries if the agent navigates or executes page scripts in the active session.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
## Reliable workflow

### Step 1: Verify API limitation first
Do **not** claim “can’t do it” without checking.

Confirm from tool docs / current tool signature that `feishu_sheet` has no `add_sheet` / `create_worksheet` / `add_tab` action.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The runtime notes enumerate destructive worksheet operations such as remove, delete, move, hide, and rename without any guardrails, warnings, or requirement for user confirmation. In the context of an agent skill that uses browser runtime methods to bypass missing API support, this increases the chance that an agent or maintainer will perform unsafe tab mutations on user data, causing data loss or integrity issues.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The notes embed a concrete Feishu spreadsheet token that appears to reference a real workspace artifact rather than a generic example. Exposing live resource identifiers in shipped skill documentation can enable unintended access attempts, targeting of tenant data, or accidental reuse against the wrong spreadsheet, especially because this skill explicitly instructs browser-runtime manipulation of sheets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.