T09 · Insecure Skill Coding Practices
- Location
scripts/import_bills_pipeline.py:63- Finding
Feishu Application Secret Exposed Through Child-Process Command-Line Arguments
- Content
View full analysis
Vulnerability Details
File Location:
scripts/import_bills_pipeline.py:63-67, 90-97, 110-116;scripts/add_manual_record.py:79-92
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: HighVulnerable Code
scripts/import_bills_pipeline.py:python env = os.environ.copy() if args.app_id: env["FEISHU_APP_ID"] = args.app_id if args.app_secret: env["FEISHU_APP_SECRET"] = args.app_secret cmd = [ sys.executable, str(PRECHECK), str(normalized_path), "--app-token", args.app_token, "--table-id", args.table_id, "--output-dir", str(precheck_dir), ] if args.app_id: cmd.extend(["--app-id", args.app_id]) if args.app_secret: cmd.extend(["--app-secret", args.app_secret])The write stage repeats the same behavior:
python if args.write: cmd = [ sys.executable, str(WRITE), str(new_records_csv), "--app-token", args.app_token, "--table-id", args.table_id, ] if args.app_id: cmd.extend(["--app-id", args.app_id]) if args.app_secret: cmd.extend(["--app-secret", args.app_secret])scripts/add_manual_record.py:python with tempfile.NamedTemporaryFile("w", suffix=".json", encoding="utf-8", delete=False) as tmp: json.dump(row, tmp, ensure_ascii=False, indent=2) tmp_path = tmp.name cmd = [ sys.executable, str(WRITE_SCRIPT), tmp_path, "--app-token", args.app_token, "--table-id", args.table_id, "--app-id", args.app_id, "--app-secret", args.app_secret, ] proc = subprocess.run(cmd, text=True, capture_output=True)Technical Analysis
The wrappers correctly place the Feishu application secret in a child-process environment, but then unnecessarily duplicate the secret in the child process's argument vector. Command-line arguments may be visible through ...[truncated 1707 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove every
cmd.extend(["--app-secret", args.app_secret])operation. -
Remove
"--app-secret", args.app_secretfromadd_manual_record.py. -
Pass the credential only through a minimally scoped child-process environment:
python child_env = os.environ.copy() child_env["FEISHU_APP_ID"] = args.app_id child_env["FEISHU_APP_SECRET"] = args.app_secret subprocess.run(cmd, env=child_env, ...) -
Prefer a dedicated secret manager or file descriptor where the runtime supports one.
-
Deprecate the
--app-secretoption because supplying a secret directly on an operator command line has the same exposure risk. -
Ensure exceptions, debugging output, and telemetry redact credentials.
-
Rotate any secret that may already have been exposed through process logs or monitoring systems.
-
Restrict the Feishu application to only the Bitable scopes and ledger resources required by this Skill.
-
