Back to skill

Security audit

Family Bookkeeping

Security checks for vulnerabilities and agentic risk

Overview

The skill is broadly coherent for Feishu-backed family bookkeeping, but it needs review because it can expose Feishu secrets and change live ledger data without strong safeguards.

Install only if you are comfortable granting the skill access to your Feishu Bitable ledger and app credentials. Prefer environment variables over command-line secrets, use a narrowly scoped Feishu app, test with dry-run or non-production data first, review generated CSVs before opening them in spreadsheet software, and clean temporary/output files that may contain household financial records.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/import_bills_pipeline.py:63
Finding

Feishu Application Secret Exposed Through Child-Process Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/import_bills_pipeline.py:63-67, 90-97, 110-116; scripts/add_manual_record.py:79-92
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: High

Vulnerable Code

scripts/import_bills_pipeline.py:

python
env = os.environ.copy()
if args.app_id:
    env["FEISHU_APP_ID"] = args.app_id
if args.app_secret:
    env["FEISHU_APP_SECRET"] = args.app_secret

cmd = [
    sys.executable,
    str(PRECHECK),
    str(normalized_path),
    "--app-token", args.app_token,
    "--table-id", args.table_id,
    "--output-dir", str(precheck_dir),
]
if args.app_id:
    cmd.extend(["--app-id", args.app_id])
if args.app_secret:
    cmd.extend(["--app-secret", args.app_secret])

The write stage repeats the same behavior:

python
if args.write:
    cmd = [
        sys.executable,
        str(WRITE),
        str(new_records_csv),
        "--app-token", args.app_token,
        "--table-id", args.table_id,
    ]
    if args.app_id:
        cmd.extend(["--app-id", args.app_id])
    if args.app_secret:
        cmd.extend(["--app-secret", args.app_secret])

scripts/add_manual_record.py:

python
with tempfile.NamedTemporaryFile("w", suffix=".json", encoding="utf-8", delete=False) as tmp:
    json.dump(row, tmp, ensure_ascii=False, indent=2)
    tmp_path = tmp.name

cmd = [
    sys.executable,
    str(WRITE_SCRIPT),
    tmp_path,
    "--app-token", args.app_token,
    "--table-id", args.table_id,
    "--app-id", args.app_id,
    "--app-secret", args.app_secret,
]
proc = subprocess.run(cmd, text=True, capture_output=True)

Technical Analysis

The wrappers correctly place the Feishu application secret in a child-process environment, but then unnecessarily duplicate the secret in the child process's argument vector. Command-line arguments may be visible through ...[truncated 1707 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove every cmd.extend(["--app-secret", args.app_secret]) operation.

  2. Remove "--app-secret", args.app_secret from add_manual_record.py.

  3. Pass the credential only through a minimally scoped child-process environment:

    python
    child_env = os.environ.copy()
    child_env["FEISHU_APP_ID"] = args.app_id
    child_env["FEISHU_APP_SECRET"] = args.app_secret
    subprocess.run(cmd, env=child_env, ...)
    
  4. Prefer a dedicated secret manager or file descriptor where the runtime supports one.

  5. Deprecate the --app-secret option because supplying a secret directly on an operator command line has the same exposure risk.

  6. Ensure exceptions, debugging output, and telemetry redact credentials.

  7. Rotate any secret that may already have been exposed through process logs or monitoring systems.

  8. Restrict the Feishu application to only the Bitable scopes and ledger resources required by this Skill.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/bookkeeping_query_live.py:87
Finding

Plaintext Household Financial Records Persist in Undeleted Temporary Files

Content
View full analysis

Vulnerability Details

File Location: scripts/bookkeeping_query_live.py:87-121; scripts/add_manual_record.py:79-105
Vulnerability Type: Unsafe temporary-file handling and plaintext sensitive-data retention
Risk Level: Medium

Vulnerable Code

scripts/bookkeeping_query_live.py retrieves the full ledger and creates a persistent temporary copy:

python
client = FeishuClient(args.app_id, args.app_secret)
records = client.list_records(args.app_token, args.table_id)
fields_rows = [r.get("fields", {}) for r in records]

if args.recent > 0:
    def sort_key(row):
        v = row.get("日期")
        if isinstance(v, (int, float)):
            return float(v)
        return 0
    rows = sorted(fields_rows, key=sort_key, reverse=True)[:args.recent]
    print(json.dumps({"recent": rows}, ensure_ascii=False, indent=2))
    return

with tempfile.NamedTemporaryFile("w", suffix=".json", encoding="utf-8", delete=False) as tmp:
    json.dump({"records": [{"fields": row} for row in fields_rows]}, tmp, ensure_ascii=False)
    tmp_path = tmp.name

cmd = [sys.executable, str(REPORT_SCRIPT), tmp_path, "--top", str(args.top)]
if args.month:
    cmd.extend(["--month", args.month])
if args.bookkeeper:
    cmd.extend(["--bookkeeper", args.bookkeeper])
if args.category:
    cmd.extend(["--category", args.category])
if args.platform:
    cmd.extend(["--platform", args.platform])
if args.income_expense:
    cmd.extend(["--income-expense", args.income_expense])

proc = subprocess.run(cmd, text=True, capture_output=True)
if proc.returncode != 0:
    sys.stderr.write(proc.stderr or proc.stdout)
    raise SystemExit(proc.returncode)
print(proc.stdout)

scripts/add_manual_record.py also persists a plaintext transaction:

python
with tempfile.NamedTemporaryFile("w", suffix=".json", encoding="utf-8", delete=False) as tmp:
    json.dump(row, tmp, ensure_ascii=False, indent=2)
    t
...[truncated 2129 chars]
Remediation
View remediation

Remediation Suggestions

  1. Perform reporting in-process so the complete ledger does not need to be serialized.

  2. If a file is unavoidable, use TemporaryDirectory or unlink it in a finally block:

    python
    tmp_path = None
    try:
        with tempfile.NamedTemporaryFile(
            "w", suffix=".json", encoding="utf-8", delete=False
        ) as tmp:
            tmp_path = tmp.name
            json.dump(data, tmp, ensure_ascii=False)
        subprocess.run(cmd, check=True, ...)
    finally:
        if tmp_path:
            Path(tmp_path).unlink(missing_ok=True)
    
  3. Apply restrictive permissions and avoid shared temporary directories where practical.

  4. Retrieve only the records and fields required by the requested query when supported by the Feishu API.

  5. Clean up files after failures, keyboard interrupts, and subprocess exceptions.

  6. Document retention behavior for intentionally generated import artifacts and distinguish those artifacts from ephemeral processing files.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/export_feishu_import_csv.py:50
Finding

Untrusted Bill Data Is Exported to CSV Without Spreadsheet Formula Neutralization

Content
View full analysis

Vulnerability Details

File Location: scripts/export_feishu_import_csv.py:50-75; scripts/import_precheck.py:217-224; source propagation in scripts/normalize_bills.py:125-158
Vulnerability Type: CSV and spreadsheet formula injection
Risk Level: Medium

Vulnerable Code

scripts/export_feishu_import_csv.py copies text fields directly into CSV cells:

python
def convert(rows):
    out = []
    for row in rows:
        item = {
            "家庭记账": primary_title(row),
            "日期": clean(row.get("日期")),
            "金额": clean(row.get("金额")),
            "记账人": clean(row.get("记账人")),
            "一级类型": clean(row.get("一级类型")),
            "二级类型": clean(row.get("二级类型")),
            "备注": clean(row.get("备注")),
            "收支类型": clean(row.get("收支类型")),
            "支付平台": clean(row.get("支付平台")),
            "导入来源": clean(row.get("导入来源")),
            "流水号": clean(row.get("流水号")),
        }
        out.append(item)
    return out


def write_csv(rows, output):
    with open(output, "w", encoding="utf-8-sig", newline="") as f:
        writer = csv.DictWriter(f, fieldnames=CANONICAL_OUT_FIELDS)
        writer.writeheader()
        writer.writerows(rows)

scripts/import_precheck.py has an additional unsanitized CSV output path:

python
def write_csv(path: Path, rows: List[Dict[str, str]], extra_fields: Optional[List[str]] = None) -> None:
    fields = list(CANONICAL_FIELDS)
    if extra_fields:
        fields.extend(extra_fields)
    with open(path, "w", encoding="utf-8-sig", newline="") as f:
        writer = csv.DictWriter(f, fieldnames=fields)
        writer.writeheader()
        for row in rows:
            writer.writerow({k: row.get(k, "") for k in fields})

Imported merchant and note data reaches these outputs through normalization:

python
note = build_note(row.get("商品"), row.get("交易对方"), row.get("备注"))
...
return {
    "
...[truncated 2330 chars]
Remediation
View remediation

Remediation Suggestions

  1. Introduce one centralized CSV-safety function and apply it to every textual output cell:

    python
    def csv_safe(value):
        text = "" if value is None else str(value)
        if text.startswith(("=", "+", "-", "@")):
            return "'" + text
        return text
    
  2. Apply neutralization in both export_feishu_import_csv.py and import_precheck.py.

  3. Consider leading whitespace, tabs, carriage returns, and other client-specific formula bypasses before checking the first effective character.

  4. Preserve numeric fields as validated numeric values rather than applying blanket text transformations.

  5. Confirm that the chosen escaping convention is compatible with Feishu Bitable's CSV importer.

  6. Add tests using payloads beginning with =, +, -, @, tab, and carriage return.

  7. Warn operators not to open untrusted generated CSV files in spreadsheet clients until neutralization is implemented.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/usage.md:5
Finding

Operational Instructions Encourage Reading a Shared Workspace Credential File

Content
View full analysis

Vulnerability Details

File Location: references/usage.md:5-23; references/feishu-import.md:15-19
Vulnerability Type: Excessive credential-file access beyond the required environment-variable scope
Risk Level: Medium

Vulnerable Instruction

references/usage.md states:

markdown
## Default Ledger Configuration

Default ledger information should be read from `~/.openclaw/workspace/.env`:

- `FAMILY_BOOKKEEPING_APP_TOKEN`
- `FAMILY_BOOKKEEPING_TABLE_ID`
- `FAMILY_BOOKKEEPING_BITABLE_URL`

## Environment Variables

Feishu credentials and default ledger settings are expected from environment variables:

- `FEISHU_APP_ID`
- `FEISHU_APP_SECRET`
- `FAMILY_BOOKKEEPING_APP_TOKEN`
- `FAMILY_BOOKKEEPING_TABLE_ID`
- `FAMILY_BOOKKEEPING_BITABLE_URL`

In most cross-channel runs, explicit `--app-id` / `--app-secret` flags are unnecessary when the environment is already configured.

references/feishu-import.md similarly directs the runtime toward the shared file:

markdown
Target ledger configuration should come from `~/.openclaw/workspace/.env`:

- `FAMILY_BOOKKEEPING_APP_TOKEN`
- `FAMILY_BOOKKEEPING_TABLE_ID`
- `FAMILY_BOOKKEEPING_BITABLE_URL`

Technical Analysis

The scripts themselves use os.getenv to obtain specific named values, which is appropriately scoped. The reference instructions, however, tell an Agent or operator to read a shared workspace .env file. Such a file may contain unrelated service credentials in addition to the five variables required by this Skill.

Reading or displaying the complete file is broader than the Skill's minimum requirements and can bring unrelated credentials into Agent context, command output, logs, or conversation history. No evidence was found that the scripts transmit those unrelated credentials to an external destination; the issue is unnecessary access and exposure.

Attack Path

  1. The Skill loads or follows the operat ...[truncated 829 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the file-reading instruction with: “Use only the named runtime environment variables.”
  2. Do not instruct an Agent to print, display, or read the complete shared .env file.
  3. If file-based loading is unavoidable, parse an explicit allowlist of variable names without exposing other entries.
  4. Store bookkeeping credentials in a dedicated file or secret namespace with restrictive permissions rather than a shared workspace file.
  5. Keep SKILL.md and all references consistent with the safer os.getenv model already used by the scripts.
  6. Ensure diagnostic messages report only missing variable names and never their values.
  7. Apply least-privilege scopes to the Feishu application so disclosure of the bookkeeping credentials has a constrained impact.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a comprehensive family bookkeeping skill with Feishu Bitable backend support, CRUD operations, bill import/export, and natural-language management of a shared household ledger. The supplied code does not implement those functions. It is only a local reporting utility: it reads JSON or CSV files, parses dates and amounts, filters rows on specified fields, and computes aggregate summaries. While monthly summaries, category breakdowns, member-based spending analysis, and platform analysis are partially consistent with the declared analytical features, the code lacks the core declared capabilities such as Feishu Bitable integration, entry creation/modification/deletion, duplicate-safe import handling, and conversational bookkeeping workflows. Therefore the actual behavior is materially narrower and different from the declared purpose.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bookkeeping_query_live.py (reported line 35)May include surrounding context.

python
resp.raise_for_status()
        data = resp.json()
        if data.get("code") != 0:
            raise RuntimeError(f"Failed to get tenant access token: {data}")
        self._token = data["tenant_access_token"]
        return self._token

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/import_precheck.py (reported line 179)May include surrounding context.

python
resp.raise_for_status()
        data = resp.json()
        if data.get("code") != 0:
            raise RuntimeError(f"Failed to get tenant access token: {data}")
        self._token = data["tenant_access_token"]
        return self._token

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/write_feishu_records.py (reported line 86)May include surrounding context.

python
resp.raise_for_status()
        data = resp.json()
        if data.get("code") != 0:
            raise RuntimeError(f"Failed to get tenant access token: {data}")
        self._token = data["tenant_access_token"]
        return self._token

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/import_bills_pipeline.py (reported line 63)May include surrounding context.

python
precheck_dir.mkdir(parents=True, exist_ok=True)
    final_import_csv = workdir / "feishu-import-new-records.csv"

    env = os.environ.copy()
    if args.app_id:
        env["FEISHU_APP_ID"] = args.app_id
    if args.app_secret:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises broad operational behavior and references environment variables, scripts, file processing, and Feishu-backed workflows, but it does not declare any explicit tool scope such as allowed-tools or permissions. In an agent runtime, that ambiguity can enable over-broad access to env, shell, filesystem, or network capabilities beyond what users would reasonably expect, increasing the chance of unauthorized data access or destructive actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description defines invocation examples entirely in Chinese, such as "记一笔", "记账", and related phrases, which signals a language-specific activation model. The file does not offer an opt-in language choice or explain that the skill is intentionally limited to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This section tells the agent to prefer the skill when the user says or implies a list of Chinese phrases and examples, but it does not indicate that other languages are supported or that the Chinese-only scope is deliberate for compliance or regional reasons. That creates a natural-language locale policy concern under the stated rules.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file explicitly instructs operators to read FEISHU_APP_ID, FEISHU_APP_SECRET, and ledger tokens from ~/.openclaw/workspace/.env and environment variables. Because these are sensitive credentials, the skill description should warn users about secret handling and avoiding exposure in shared environments or logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown describes --write as performing actual Feishu writes and also includes a direct record-update command, but it does not prominently warn that these commands change live shared bookkeeping data and may be difficult to undo. For markdown files, behaviors affecting user data or system integrity should be accompanied by explicit warnings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language handling is implemented only for Chinese phrases such as '昨天', '午饭', and '打车', and several output/default field values are also fixed in Chinese. There is no opt-in, locale selection, or documentation indicating that the skill is intentionally limited to Chinese-language input.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code builds a subprocess command containing app token, table ID, app ID, and app secret, and uses it to submit the generated record for writing. The file has no confirmation prompt, no user-facing notice before transmission, and no comments/docstring warning that user-entered notes and credentials will be used for a remote write operation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/bookkeeping_query_live.py (reported line 31)May include surrounding context.

python
if self._token:
            return self._token
        url = f"{OPEN_API_BASE}/auth/v3/tenant_access_token/internal"
        resp = requests.post(url, json={"app_id": self.app_id, "app_secret": self.app_secret}, timeout=self.timeout)
        resp.raise_for_status()
        data = resp.json()
        if data.get("code") != 0:

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/import_precheck.py (reported line 175)May include surrounding context.

python
if self._token:
            return self._token
        url = f"{OPEN_API_BASE}/auth/v3/tenant_access_token/internal"
        resp = requests.post(url, json={"app_id": self.app_id, "app_secret": self.app_secret}, timeout=self.timeout)
        resp.raise_for_status()
        data = resp.json()
        if data.get("code") != 0:

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/recent_records.py (reported line 39)May include surrounding context.

python
if self._token:
            return self._token
        url = f"{OPEN_API_BASE}/auth/v3/tenant_access_token/internal"
        resp = requests.post(url, json={"app_id": self.app_id, "app_secret": self.app_secret}, timeout=self.timeout)
        resp.raise_for_status()
        data = resp.json()
        if data.get("code") != 0:

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/update_record_mvp.py (reported line 52)May include surrounding context.

python
if self._token:
            return self._token
        url = f"{OPEN_API_BASE}/auth/v3/tenant_access_token/internal"
        resp = requests.post(url, json={"app_id": self.app_id, "app_secret": self.app_secret}, timeout=self.timeout)
        resp.raise_for_status()
        data = resp.json()
        if data.get("code") != 0:

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/write_feishu_records.py (reported line 82)May include surrounding context.

python
if self._token:
            return self._token
        url = f"{OPEN_API_BASE}/auth/v3/tenant_access_token/internal"
        resp = requests.post(url, json={"app_id": self.app_id, "app_secret": self.app_secret}, timeout=self.timeout)
        resp.raise_for_status()
        data = resp.json()
        if data.get("code") != 0:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script sends authentication data to Feishu via requests.post and later retrieves live records via requests.get, which transmits user/system data over the network. There is no visible confirmation prompt, logging, comment, or other warning in this file disclosing that remote API calls will be made against a live bookkeeping service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code accepts FEISHU_APP_ID and FEISHU_APP_SECRET from environment variables and exits if they are missing, but it provides no print, comment, or other user-facing disclosure that sensitive credentials will be accessed. Under the code-file criteria, sensitive environment-variable access should be flagged when there is no visible warning or explanation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script writes all retrieved bookkeeping records to a temporary file with delete=False, which leaves potentially sensitive family financial data on local disk after execution. On shared systems, backups, crash dumps, or later local compromise could expose this residual data unnecessarily.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/bookkeeping_query_live.py (reported line 116)May include surrounding context.

python
if args.income_expense:
        cmd.extend(["--income-expense", args.income_expense])

    proc = subprocess.run(cmd, text=True, capture_output=True)
    if proc.returncode != 0:
        sys.stderr.write(proc.stderr or proc.stdout)
        raise SystemExit(proc.returncode)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/import_bills_pipeline.py (reported line 20)May include surrounding context.

python
def run(cmd, env=None):
    proc = subprocess.run(cmd, text=True, capture_output=True, env=env)
    if proc.returncode != 0:
        sys.stderr.write(proc.stderr or proc.stdout)
        raise SystemExit(proc.returncode)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This pipeline supports a --write mode that can directly modify Feishu Bitable records after import precheck, but this file provides no interactive confirmation, dry-run default enforcement beyond the flag itself, or explicit safety warning at the point of write. In a bookkeeping skill handling shared family financial data, accidental writes can corrupt records or create unauthorized changes if the command is triggered unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script performs a live remote update to a Feishu Bitable record as soon as a single match is found, without any built-in confirmation prompt, approval gate, or default dry-run behavior. In a bookkeeping skill, this can silently alter financial records if upstream natural-language matching is wrong or if the script is invoked with unintended parameters, leading to integrity loss in shared family ledger data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code performs non-dry-run remote record creation in Feishu, which is a safety-relevant write operation affecting user data. Although a --dry-run mode exists, the normal execution path writes immediately and only prints a summary afterward, with no confirmation prompt or explicit user-facing warning at the point of action.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.