Back to skill

Security audit

Feishu Bot Config Helper

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Feishu bot configuration helper, but it needs review because it asks for bot secrets in chat, installs mutable remote code, and creates broad bot access by default.

Install only after reviewing the installer and preferably pinning it to a trusted commit. Do not paste production Feishu App Secrets into chat or logs unless you accept that retention risk. Before running the configurator, back up openclaw.json, review the generated agent permissions, replace wildcard allowFrom with explicit trusted users, avoid skills all unless required, and plan for Gateway restart downtime.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:29
Finding

Unpinned Remote Installer Is Executed Directly by Bash

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
install.sh:17
Finding

Installer Clones Mutable Supply-Chain Content and Runs npm Install

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/auto-configure-bot.js:252
Finding

Wildcard Direct-Message Access and Open Group Policy Expose Configured Agents

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:61
Finding

Realistic Feishu App Secret Is Embedded in Documentation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (21)

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs users to submit App ID and App Secret directly in chat-based configuration messages. In this context, chat transcripts, agent logs, prompt history, and downstream reporting may retain those credentials, creating a direct path to credential disclosure and unauthorized control of the Feishu bot integration.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Using '| bash' chains network retrieval directly into shell execution, eliminating opportunities for inspection or validation before code runs. In this skill's context, the command is presented as the primary installation path for an automation tool that changes bot configuration and restarts infrastructure, which amplifies the risk of host compromise and unauthorized operational changes.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Mac / Linux

bash
curl -fsSL https://raw.githubusercontent.com/jiebao360/feishu-bot-config-helper/main/install.sh | bash

Windows

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/auto-configure-bot.js (reported line 124)May include surrounding context.

js
for (const rule of rules) {
      for (const keyword of rule.keywords) {
        if (nameLower.includes(keyword.toLowerCase())) {
          return rule;
        }
      }
    }

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The changelog states that the system will automatically update openclaw.json and restart the gateway, but does not indicate safeguards, authorization checks, confirmation steps, or user-visible warnings. In an auto-configuration feature, undocumented config mutation and service restarts are security-relevant because they can enable unauthorized operational changes, disrupt availability, or apply attacker-influenced settings if upstream inputs are not tightly controlled.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The changelog documents keyword-based agent routing using broad, everyday terms like '内容', '通用', '工作', and '助手'. In a chat-driven bot configuration context, these overlapping triggers can cause users or attackers to unintentionally or deliberately select the wrong agent, leading to misrouting of conversations, incorrect workspace/memory isolation, or unintended capability exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README advertises automatic updates to openclaw.json and automatic Gateway restarts without any warning, confirmation, rollback guidance, or scope limitation. In an agent skill context, undocumented system-changing actions can surprise operators and lead to unsafe configuration drift or service disruption if triggered from chat-driven input.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation includes plaintext App Secret examples and does not warn users to treat them as credentials or avoid sharing real secrets in chat, logs, screenshots, or examples. This normalizes unsafe secret handling and increases the chance that operators will paste production credentials into conversational channels that may be stored or observed.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The sample report echoes back user-supplied configuration details and presents that pattern as normal post-setup behavior. Even though the example visibly shows only App ID, the documented workflow elsewhere collects App Secret, so reporting conventions that reflect input values increase the risk that secrets will be echoed, logged, or exposed in operator-visible output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises automatic Agent creation, workspace configuration, file updates, and Gateway restarts without an explicit upfront warning about these side effects or their operational impact. In a skill context, undisclosed state-changing behavior can cause administrators to run it without understanding that it will alter configuration and disrupt service availability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installer clones code from a remote GitHub repository and immediately runs npm install, which can execute lifecycle scripts from the downloaded package and its dependencies. This creates a real supply-chain and remote-code-execution risk, especially because the script provides no warning, integrity verification, pinning, or review step before executing untrusted external code.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The header comment says the script supports directly configuring a new bot and automatically creating an Agent, workspace, and bindings. However, in addAgent the code checks for an existing agent ID and updates that agent's name, workspace, and skills when present, which is a materially different action from only creating a new bot configuration.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/auto-configure-bot.js (reported line 172)May include surrounding context.

js
return;
      }

      exec(`mkdir -p "${workspacePath}"`, (error) => {
        if (error) {
          console.error('❌ 创建工作空间失败:', error.message);
        } else {

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/auto-configure-bot.js (reported line 172)May include surrounding context.

js
return;
      }

      exec(`mkdir -p "${workspacePath}"`, (error) => {
        if (error) {
          console.error('❌ 创建工作空间失败:', error.message);
        } else {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script writes credentials into the main configuration and restarts the gateway immediately, with no confirmation, dry-run, or rollback step. In an agent-skill context, that makes a single supplied message capable of persistently changing bot routing and service state, increasing the risk of unauthorized or accidental reconfiguration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

All user-facing natural-language content in this file is Chinese, and there is no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking context. This may conflict with a language/locale policy requiring user opt-in or documented justification for locale constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The entire skill document is written in Chinese and presents the skill as a general-purpose configuration assistant, but it does not indicate that Chinese is optional or that the skill is intended only for a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to fetch and execute a remote script directly from GitHub using curl piped to bash. This is dangerous because the downloaded content is not pinned, verified, or reviewed locally, so any repository compromise, malicious update, or network-layer tampering could lead to immediate arbitrary code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Mac / Linux

bash
curl -fsSL https://raw.githubusercontent.com/jiebao360/feishu-bot-config-helper/main/install.sh | bash

Windows

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's prompts and usage text are entirely in Chinese, which imposes a specific language on all users without offering an alternative or documenting that the skill is intended only for Chinese-speaking users. This matches the policy concern for language or locale constraints without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

Natural-language parsing in this skill depends on Chinese phrases such as '配置飞书机器人:' and '创建技能', and the user-facing help/output is also Chinese-only. That enforces a specific language/locale behavior without any opt-in or alternative, which conflicts with the language-choice policy.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

generateReport always says '✅ 添加路由绑定' was completed. In addBinding, if a matching binding already exists, the function logs that it is skipping the operation and returns false, so the report can contradict the actual behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The report always states '✅ 创建工作空间目录' as a completed action. But createWorkspace resolves successfully both when it creates the directory and when it merely finds an existing workspace, so the report can assert creation that never happened.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/auto-configure-bot.js:172