Back to skill

Security audit

Feishu Notes Bot

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Feishu notes workflow with disclosed cloud sync and credential setup, with no evidence of hidden execution, persistence, or unrelated data transfer.

Before installing, confirm that your organization allows meeting notes, attendee names, action items, and project details to be stored in Feishu cloud documents, and keep the Feishu app secret private. Review Feishu document permissions so notes are shared only with intended users.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes creating, querying, and syncing notes and meeting records to Feishu cloud documents, but it does not clearly warn users that potentially sensitive meeting content, participant names, and notes may be transmitted to and stored on third-party cloud infrastructure. This can lead to unintended disclosure of confidential business or personal information because users are encouraged to use the bot for meeting capture without informed consent about remote storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The examples explicitly encourage users to send meeting content, attendees, and discussion details to the bot, which then saves the data to Feishu cloud documents, yet no privacy or confidentiality warning accompanies these workflows. In context, this increases the chance that sensitive internal information will be shared externally without users appreciating the data handling boundary.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

获取访问令牌:

bash
curl -X POST "https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal" \
  -H "Content-Type: application/json" \
  -d '{
    "app_id": "cli_xxx",

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown template uses Chinese headings and labels throughout, but does not mention that the language is optional, user-selected, or limited to a Chinese-language context. That can violate the language/locale policy because it implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.