T09 · Insecure Skill Coding Practices
- Location
scripts/daily-push.js:11- Finding
Hard-Coded Feishu Application Credentials and Recipient
- Content
View full analysis
{ const req = https.request( 'https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal', { method: 'POST', headers: { 'Content-Type': 'application/json', 'Content-Length': data.length } }, (res) => { let body = ''; res.on('data', chunk => body += chunk); res.on('end', () => { const result = JSON.parse(body); resolve(result.tenant_access_token); }); } ); req.on('error', reject); req.write(data); req.end(); }); } ``` The report is then sent to the embedded recipient: ```javascript const payload = { receive_id: FEISHU_CONFIG.receiveId, msg_type: 'text', content: JSON.stringify({ text: content }) }; ``` ### Technical Analysis A Feishu application ID, application secret, and recipient open ID are stored directly in source code. The application secret is an authentication credential used to obtain a tenant access token. Anyone who obtains a copy of the project can extract this credential and attempt to authenticate as the Feishu application. The main scheduled entry point, `scripts/daily-push.js`, does not use the destinations described by the configurable webhook mechanism ...[truncated 2055 chars]- Remediation
View remediation
