Back to skill

Security audit

Feishu Cli Auth

Security checks for vulnerabilities and agentic risk

Overview

The skill is openly about Feishu OAuth login, but it directs agents to request broad long-lived permissions by default and store sensitive tokens locally.

Install only if you are comfortable granting broad Feishu account access to the CLI and agent workflow. Prefer narrower scopes when possible, avoid pasting callback URLs into shared logs or transcripts, protect ~/.feishu-cli/token.json, and revoke Feishu app authorization if the token may have been exposed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:40
Finding

Mandatory Over-Privileged OAuth Authorization

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:62
Finding

OAuth Authorization Code Passed Through Process Arguments

Content
View full analysis
" --state "" ``` The documented concrete form is: ```bash feishu-cli auth callback "http://127.0.0.1:9768/callback?code=xxx&state=yyy" --state "yyy" ``` ### Technical Analysis The callback URL contains a short-lived OAuth authorization code. The Skill instructs the agent to place the entire URL directly in the command line, making the code part of the process argument vector. Depending on the host and agent environment, command arguments may be visible through: - Process-inspection interfaces while the command is running. - Agent tool-call transcripts and execution telemetry. - Shell tracing, debug output, or command history. - Audit systems and centralized process logging. - Error reports that record the original command. The separate `state` value is also exposed. OAuth state primarily protects against request forgery and callback mix-ups; it is not a substitute for keeping the authorization code confidential. Successful misuse remains dependent on the OAuth implementation. An attacker may also need the application’s token-exchange credentials or a matching PKCE verifier if PKCE is enforced. The `feishu-cli` implementation is absent from the audited project, so those mitigating controls cannot be verified. ### Attack Path 1. The agent generates an OAuth authorization URL and state value. 2. The user authorizes access and returns the complete callback URL containing the authorization code. 3. The agent invokes `feishu-cli auth callback` with that URL as a command-line argument. 4. A local process observer, tool transcript, telemetry system, or command logger captures the argument before the code expires. 5. ...[truncated 865 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (19)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: feishu-cli-auth
description: >-
  飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
  Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
  当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
  "搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
---
name: feishu-cli-auth
description: >-
  飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
  Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
  当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
  "搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
---
name: feishu-cli-auth
description: >-
  飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
  Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
  当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
  "搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
---
name: feishu-cli-auth
description: >-
  飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
  Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
  当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
  "搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
---
name: feishu-cli-auth
description: >-
  飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
  Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
  当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
  "搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
---
name: feishu-cli-auth
description: >-
  飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
  Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
  当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
  "搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
---
name: feishu-cli-auth
description: >-
  飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
  Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
  当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
  "搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

md
---
name: feishu-cli-auth
description: >-
  飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
  Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
  当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
  "搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 319)May include surrounding context.

md
---
name: feishu-cli-auth
description: >-
  飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
  Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
  当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
  "搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 327)May include surrounding context.

md
---
name: feishu-cli-auth
description: >-
  飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
  Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
  当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
  "搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 328)May include surrounding context.

md
---
name: feishu-cli-auth
description: >-
  飞书 OAuth 认证和 User Access Token 管理。两步式非交互登录(AI Agent 专用)、
  Token 状态检查、scope 配置、自动刷新机制、搜索功能的 Token 依赖关系。
  当用户请求"登录飞书"、"获取 Token"、"OAuth 授权"、"auth login"、"认证"、
  "搜索需要什么权限"、"Token 过期了"、"刷新 Token"时使用。

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

This line documents persistent local storage of access and refresh tokens in a fixed path, creating credential exposure risk if the file is readable by other users, included in backups, or surfaced in agent workflows. Because refresh tokens can mint new access tokens, the persistence materially increases the blast radius of host or workflow compromise.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
## 核心概念

**Token 存储位置**:所有 OAuth Token 保存在 `~/.feishu-cli/token.json`,包括 Access Token、Refresh Token、过期时间和授权 scope。登录、刷新、退出等操作都围绕此文件进行。

**两种身份**:
- **App Access Token**(应用身份):通过 app_id/app_secret 自动获取,大多数文档操作使用此身份

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The documented token resolution chain includes command-line arguments and environment variables for user access tokens. These channels are often exposed via process listings, shell history, CI logs, or debugging output, so presenting them as normal input paths without warning increases the risk of credential disclosure.

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

md
## Token 自动刷新机制

搜索、消息互动、群聊管理等**必须** User Access Token 的命令(`resolveRequiredUserToken`)通过 `ResolveUserAccessToken()` 按以下优先级链查找。其他可选命令(`resolveOptionalUserToken`)仅检查第 1、2 项,默认使用 App Token:

1. `--user-access-token` 命令行参数
2. `FEISHU_USER_ACCESS_TOKEN` 环境变量

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill endorses static configuration of user access tokens in config.yaml and silent automatic refresh/save behavior, which can leave long-lived credentials resident in files that are easily copied, backed up, or committed. This normalizes insecure credential persistence patterns in a user-invocable skill.

Content

Scanner excerpt · SKILL.md (reported line 215)May include surrounding context.

md
- access_token 过期 + refresh_token 有效 → **自动刷新并保存新 Token**
   - 都过期 → 报错"已过期,请重新登录"
4. `config.yaml` 中的 `user_access_token` 静态配置
5. 全部为空 → 报错"缺少 User Access Token",列出 4 种获取方式

**刷新过程对用户透明**:stderr 输出 `[自动刷新] 刷新成功...`,命令正常执行。

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

This section recommends explicit passing of user tokens through --user-access-token or FEISHU_USER_ACCESS_TOKEN for optional commands. Those mechanisms are common sources of accidental credential leakage in terminals, automation, and observability systems, especially in an agent context where outputs may be retained.

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

md
| `chat update/delete` | `im:chat` |
| `chat member list/add/remove` | `im:chat:readonly`、`im:chat.members:read`、`im:chat.members` |

### 可选 User Access Token 的命令

以下命令默认使用 App Token(租户身份),仅在通过 `--user-access-token` 参数或 `FEISHU_USER_ACCESS_TOKEN` 环境变量显式指定时才使用 User Token:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs storing OAuth access and refresh tokens in a predictable local file and recommends broad, maximum-scope authorization, but it does not warn that these tokens are highly sensitive credentials. If a user or downstream agent treats this casually, compromise of the local account, logs, backups, or shared home directory could expose long-lived tokens with broad API access.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

The skill explicitly directs agents to always request the maximum possible scope set, including read and write permissions across search, calendar, tasks, chat, and message operations, plus offline_access for long-lived refresh. This violates least privilege and meaningfully increases impact if the token, callback URL, host, or agent transcript is compromised.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

始终使用最大 scope 范围授权,一次性覆盖 feishu-cli 所有用户身份功能,避免后续因 scope 不足导致 99991679 错误:

bash
feishu-cli auth login --print-url --scopes "offline_access search:docs:read search:message drive:drive.search:readonly wiki:wiki:readonly calendar:calendar:read calendar:calendar.event:read calendar:calendar.event:create calendar:calendar.event:update calendar:calendar.event:reply calendar:calendar.free_busy:read task:task:read task:task:write task:tasklist:read task:tasklist:write im:message:readonly im:message.group_msg:get_as_user im:chat:read im:chat:readonly im:chat.members:read contact:user.base:readonly drive:drive.metadata:readonly"

输出 JSON(stdout):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill tells the user to copy and provide the full OAuth callback URL, which contains the authorization code and state, without warning that the URL is sensitive. An agent, transcript, shell history, or shared chat log that captures this URL could enable token exchange before the code expires, resulting in unauthorized access to the user's account scopes.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

The login-before-search workflow again instructs use of the maximal scope bundle as the standard recovery path. Repeating this pattern in a user-facing procedure normalizes persistent over-privileged sessions and enlarges the damage from token theft or misuse across multiple Feishu services.

Content

Scanner excerpt · SKILL.md (reported line 259)May include surrounding context.

md
feishu-cli auth status -o json

# 2. 如果未登录或已过期,执行两步式登录(使用最大 scope)
feishu-cli auth login --print-url --scopes "offline_access search:docs:read search:message drive:drive.search:readonly wiki:wiki:readonly calendar:calendar:read calendar:calendar.event:read calendar:calendar.event:create calendar:calendar.event:update calendar:calendar.event:reply calendar:calendar.free_busy:read task:task:read task:task:write task:tasklist:read task:tasklist:write im:message:readonly im:message.group_msg:get_as_user im:chat:read im:chat:readonly im:chat.members:read contact:user.base:readonly drive:drive.metadata:readonly"
# ... 用户授权 ...
feishu-cli auth callback "<回调URL>" --state "<state>"

Static analysis

No suspicious patterns detected.