T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:40- Finding
Mandatory Over-Privileged OAuth Authorization
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is openly about Feishu OAuth login, but it directs agents to request broad long-lived permissions by default and store sensitive tokens locally.
Install only if you are comfortable granting broad Feishu account access to the CLI and agent workflow. Prefer narrower scopes when possible, avoid pasting callback URLs into shared logs or transcripts, protect ~/.feishu-cli/token.json, and revoke Feishu app authorization if the token may have been exposed.
SKILL.md:40Mandatory Over-Privileged OAuth Authorization
SKILL.md:62OAuth Authorization Code Passed Through Process Arguments
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: feishu-cli-auth
description: >-
飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
"搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: feishu-cli-auth
description: >-
飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
"搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: feishu-cli-auth
description: >-
飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
"搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: feishu-cli-auth
description: >-
飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
"搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: feishu-cli-auth
description: >-
飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
"搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: feishu-cli-auth
description: >-
飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
"搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: feishu-cli-auth
description: >-
飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
"搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: feishu-cli-auth
description: >-
飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
"搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: feishu-cli-auth
description: >-
飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
"搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: feishu-cli-auth
description: >-
飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
"搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: feishu-cli-auth
description: >-
飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
"搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。
This line documents persistent local storage of access and refresh tokens in a fixed path, creating credential exposure risk if the file is readable by other users, included in backups, or surfaced in agent workflows. Because refresh tokens can mint new access tokens, the persistence materially increases the blast radius of host or workflow compromise.
## 核心概念
**Token 存储位置**:所有 OAuth Token 保存在 `~/.feishu-cli/token.json`,包括 Access Token、Refresh Token、过期时间和授权 scope。登录、刷新、退出等操作都围绕此文件进行。
**两种身份**:
- **App Access Token**(应用身份):通过 app_id/app_secret 自动获取,大多数文档操作使用此身份
The documented token resolution chain includes command-line arguments and environment variables for user access tokens. These channels are often exposed via process listings, shell history, CI logs, or debugging output, so presenting them as normal input paths without warning increases the risk of credential disclosure.
## Token 自动刷新机制
搜索、消息互动、群聊管理等**必须** User Access Token 的命令(`resolveRequiredUserToken`)通过 `ResolveUserAccessToken()` 按以下优先级链查找。其他可选命令(`resolveOptionalUserToken`)仅检查第 1、2 项,默认使用 App Token:
1. `--user-access-token` 命令行参数
2. `FEISHU_USER_ACCESS_TOKEN` 环境变量
The skill endorses static configuration of user access tokens in config.yaml and silent automatic refresh/save behavior, which can leave long-lived credentials resident in files that are easily copied, backed up, or committed. This normalizes insecure credential persistence patterns in a user-invocable skill.
- access_token 过期 + refresh_token 有效 → **自动刷新并保存新 Token**
- 都过期 → 报错"已过期,请重新登录"
4. `config.yaml` 中的 `user_access_token` 静态配置
5. 全部为空 → 报错"缺少 User Access Token",列出 4 种获取方式
**刷新过程对用户透明**:stderr 输出 `[自动刷新] 刷新成功...`,命令正常执行。
This section recommends explicit passing of user tokens through --user-access-token or FEISHU_USER_ACCESS_TOKEN for optional commands. Those mechanisms are common sources of accidental credential leakage in terminals, automation, and observability systems, especially in an agent context where outputs may be retained.
| `chat update/delete` | `im:chat` |
| `chat member list/add/remove` | `im:chat:readonly`、`im:chat.members:read`、`im:chat.members` |
### 可选 User Access Token 的命令
以下命令默认使用 App Token(租户身份),仅在通过 `--user-access-token` 参数或 `FEISHU_USER_ACCESS_TOKEN` 环境变量显式指定时才使用 User Token:
The skill explicitly instructs storing OAuth access and refresh tokens in a predictable local file and recommends broad, maximum-scope authorization, but it does not warn that these tokens are highly sensitive credentials. If a user or downstream agent treats this casually, compromise of the local account, logs, backups, or shared home directory could expose long-lived tokens with broad API access.
The skill explicitly directs agents to always request the maximum possible scope set, including read and write permissions across search, calendar, tasks, chat, and message operations, plus offline_access for long-lived refresh. This violates least privilege and meaningfully increases impact if the token, callback URL, host, or agent transcript is compromised.
始终使用最大 scope 范围授权,一次性覆盖 feishu-cli 所有用户身份功能,避免后续因 scope 不足导致 99991679 错误:
feishu-cli auth login --print-url --scopes "offline_access search:docs:read search:message drive:drive.search:readonly wiki:wiki:readonly calendar:calendar:read calendar:calendar.event:read calendar:calendar.event:create calendar:calendar.event:update calendar:calendar.event:reply calendar:calendar.free_busy:read task:task:read task:task:write task:tasklist:read task:tasklist:write im:message:readonly im:message.group_msg:get_as_user im:chat:read im:chat:readonly im:chat.members:read contact:user.base:readonly drive:drive.metadata:readonly"
输出 JSON(stdout):
The skill tells the user to copy and provide the full OAuth callback URL, which contains the authorization code and state, without warning that the URL is sensitive. An agent, transcript, shell history, or shared chat log that captures this URL could enable token exchange before the code expires, resulting in unauthorized access to the user's account scopes.
The login-before-search workflow again instructs use of the maximal scope bundle as the standard recovery path. Repeating this pattern in a user-facing procedure normalizes persistent over-privileged sessions and enlarges the damage from token theft or misuse across multiple Feishu services.
feishu-cli auth status -o json
# 2. 如果未登录或已过期,执行两步式登录(使用最大 scope)
feishu-cli auth login --print-url --scopes "offline_access search:docs:read search:message drive:drive.search:readonly wiki:wiki:readonly calendar:calendar:read calendar:calendar.event:read calendar:calendar.event:create calendar:calendar.event:update calendar:calendar.event:reply calendar:calendar.free_busy:read task:task:read task:task:write task:tasklist:read task:tasklist:write im:message:readonly im:message.group_msg:get_as_user im:chat:read im:chat:readonly im:chat.members:read contact:user.base:readonly drive:drive.metadata:readonly"
# ... 用户授权 ...
feishu-cli auth callback "<回调URL>" --state "<state>"
No suspicious patterns detected.