Back to skill

Security audit

Feishu Weekly Report Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent weekly-report generator, but its bundled script has unsafe command execution and unrestricted file overwrite behavior that users should review before installing.

Install only if you are comfortable reviewing or fixing the script first. Avoid passing untrusted values to --git, --start, --end, or --output, and keep generated reports local until you have reviewed them for confidential commit messages or internal work details.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate-weekly.mjs:144
Finding

Shell Command Injection Through Git Collection Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/generate-weekly.mjs:144-147
Vulnerability Type: OS command injection
Risk Level: High

Vulnerable Code:

js
const output = execSync(
  `git -C "${gitPath}" log --since="${since} 00:00:00" --until="${until} 23:59:59" --format="${format}" --date=short`,
  { encoding: 'utf8', cwd: gitPath }
);

Technical Analysis

The values supplied through the --git, --start, and --end command-line options are inserted directly into a command string passed to execSync(). Because execSync() executes the string through a system shell, shell metacharacters and command substitutions within these values can be interpreted as executable syntax.

Enclosing the values in double quotes does not provide sufficient protection. On common shells, constructs such as command substitution remain active inside double-quoted strings. The script performs no strict date validation and does not safely separate executable arguments from the command itself.

Attack Path

  1. An attacker persuades a user or automated process to invoke the generator with a crafted --start, --end, or --git argument.
  2. parseArgs() stores the supplied value without validating it against an allowlist or strict format.
  3. generateReport() passes the values to collectGitCommits().
  4. collectGitCommits() interpolates the values into a shell command.
  5. execSync() invokes the system shell.
  6. The injected shell expression executes with the privileges of the user running the generator.

Exploitation requires the Git collection path to be reached, including a supplied --git path that passes the existence check.

Impact Assessment

Successful exploitation permits arbitrary command execution under the account that invokes the Skill. An attacker could read or modify files accessible to that account, execute local programs, access available environment data, alter repositories, ...[truncated 208 chars]

Remediation
View remediation

Remediation Suggestions

Replace shell-string execution with an API that passes arguments separately, such as execFileSync() or spawnSync():

js
const output = execFileSync(
  'git',
  [
    '-C',
    gitPath,
    'log',
    `--since=${since} 00:00:00`,
    `--until=${until} 23:59:59`,
    `--format=${format}`,
    '--date=short'
  ],
  {
    encoding: 'utf8',
    cwd: gitPath,
    shell: false
  }
);

Additionally:

  • Validate --start and --end against a strict YYYY-MM-DD format and verify that they represent valid dates.
  • Resolve and validate --git as an existing directory before use.
  • Reject missing option values and unexpected command-line arguments.
  • Avoid enabling shell execution for any subprocess call involving user-controlled data.
  • Add regression tests using shell metacharacters and command-substitution syntax to confirm that arguments are treated only as data.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate-weekly.mjs:304
Finding

Unrestricted Output Path Allows Arbitrary File Overwrite

Content
View full analysis

Vulnerability Details

File Location: scripts/generate-weekly.mjs:45-48 and scripts/generate-weekly.mjs:304
Vulnerability Type: Arbitrary file overwrite
Risk Level: Medium

Vulnerable Code:

js
case '--output':
  options.output = args[++i];
  break;
js
writeFileSync(options.output, report, 'utf8');

Technical Analysis

The --output argument is accepted without path validation and is passed directly to writeFileSync(). The default behavior of writeFileSync() truncates an existing file before writing the generated report.

The implementation does not restrict output to an approved directory, reject absolute paths or traversal sequences, detect symbolic-link destinations, or request confirmation before replacing an existing file. Consequently, any file writable by the invoking account can be selected as the destination.

Attack Path

  1. An attacker supplies or causes an automated process to use a crafted --output value.
  2. parseArgs() accepts the path without normalization or policy checks.
  3. The script generates the report.
  4. writeFileSync() opens the selected path for writing and truncates an existing destination.
  5. The target file is replaced with report content.

Exploitation requires the invoking account to have write permission for the destination. If the selected path is a symbolic link, the effective target may be outside the apparent output location.

Impact Assessment

An attacker can destroy or replace files writable by the invoking user. Potential consequences include loss of application data, corruption of configuration files, disruption of development workflows, and replacement of user-controlled scripts or other files that may later be consumed by trusted processes.

The primitive does not bypass operating-system permissions and therefore cannot directly overwrite files inaccessible to the invoking account. Its effective scope is all writ ...[truncated 52 chars]

Remediation
View remediation

Remediation Suggestions

  • Resolve output paths against a dedicated, approved report directory.
  • Reject paths that escape that directory after canonicalization.
  • Reject absolute paths unless the user explicitly opts into unrestricted output.
  • Detect existing destinations and require explicit overwrite authorization.
  • Use exclusive file creation where replacement is unnecessary, for example with the wx flag.
  • Check for symbolic links and validate the canonical parent directory before writing.
  • Validate that --output has a nonempty argument and enforce an expected file extension if appropriate.
  • For automated environments, expose a separate explicit --force option rather than overwriting files by default.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (16)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
node scripts/generate-weekly.mjs

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
node scripts/generate-weekly.mjs

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
node scripts/generate-weekly.mjs

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
node scripts/generate-weekly.mjs

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
node scripts/generate-weekly.mjs

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
node scripts/generate-weekly.mjs

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
node scripts/generate-weekly.mjs

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
node scripts/generate-weekly.mjs

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly advertises automatic collection of work data from sources like git commits, calendar events, and task completions, and also mentions optional Feishu API use, but it does not warn users about the sensitivity of that data or the risks of transmitting it to third-party services. In a workplace context, this can lead to unintentional disclosure of confidential project details, personal calendar information, or internal metadata because users are not prompted to review scope, consent, or destination before use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown template is entirely written in Chinese, including the title, section headings, and labels, which implies the generated weekly report will be produced in a fixed language. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template headings and labels are written entirely in Chinese, which imposes a specific language on generated output. There is no indication that users can opt into another language or that the template is intentionally limited to a Chinese-only regional context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template headings and labels are entirely in Chinese, which imposes a specific language on generated output. Under the policy rules, a fixed language/locale without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script collects git commit messages from the specified repository and writes them into a markdown report file. Although it logs that a report is being generated, it does not warn the user that commit messages and related work details from the repository will be included in the output, which can expose sensitive project information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill artifact is written in Chinese, including the title, section headings, and generated-report framing, with no indication that language choice is optional or limited to a justified region-specific context. Under the policy rule for natural-language violations, this constitutes a locale/language constraint that is imposed without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The documented report structure is presented entirely with Chinese section headings, while the surrounding documentation is in English and does not state that Chinese output is optional or required for Feishu users. This can violate language/locale policy if the skill defaults users into a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script hardcodes Chinese output strings, weekday names, template headings, and the fallback name '用户', which forces a specific language/locale behavior. There is no visible opt-in, locale selection, or documentation that this is intentionally limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/generate-weekly.mjs:67