Back to skill

Security audit

lark-contact

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Lark contact lookup helper, but users should treat employee profile results as permission-scoped workplace personal data.

Install only if you are comfortable letting the agent query Lark directory data available to your user account. Use it for legitimate workplace tasks, confirm ambiguous people before sending messages or invites, and avoid broad filter-only searches unless you have a valid business reason.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file advertises resolving employees by name/email and reverse-looking up a person's name, department, email, and contact information. Because this behavior exposes potentially sensitive personnel data, the description should warn that results depend on permissions and should only be used for authorized work purposes, but no such user-facing warning appears here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation materially broadens the skill from a narrow identifier-resolution helper into a richer employee directory/profile lookup tool, including complete-profile retrieval via --user-ids. In an agent setting, that expands access to organizational personal data beyond the stated purpose, increasing the chance of over-collection, unintended disclosure, and misuse by downstream workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Allowing filter-only use such as listing all chatted or departed employees turns a resolver into a directory-enumeration primitive. Even without auto-pagination, this enables systematic harvesting of employee metadata in batches and can expose sensitive organizational information unrelated to the user’s immediate task.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The examples present the command as able to '列出所有' employees matching certain filters, which implies a complete listing behavior. Later, the notes explicitly state that the command does not auto-paginate and that has_more=true requires query refinement, so the documented usage overpromises completeness relative to the stated behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.