Back to skill

Security audit

Feishu Upload Image

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims by uploading an image to Feishu, but its credential and token handling are under-protected enough to require review before installation.

Install only if you trust this publisher and are comfortable giving the script Feishu app credentials and allowing selected images to be uploaded to Feishu. Before production use, the token cache should be moved to a private user-owned directory or removed, the Python credential parsing should avoid source-code interpolation, and secret-handling warnings/tool scope should be made explicit.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/upload-image.sh:18
Finding

Feishu Bearer Token Stored in a Predictable, Insecure Temporary File

Content
View full analysis
/dev/null) local TOKEN=$(cat "$TOKEN_CACHE" | python3 -c "import sys,json; print(json.load(sys.stdin).get('token',''))" 2>/dev/null) if [ -n "$TOKEN" ] && [ "$NOW" -lt "$((EXPIRES_AT - 300))" ]; then echo "$TOKEN" return 0 fi fi ``` ```bash echo "{\"token\":\"$TOKEN\",\"expires_at\":$((NOW + EXPIRES_IN - 300))}" > "$TOKEN_CACHE" ``` ### Technical Analysis The script stores a reusable Feishu application access token in a fixed path under the shared `/tmp` directory. It does not set restrictive permissions, verify ownership, reject symbolic links, or create the file atomically. The effective permissions depend on the invoking process's `umask`. A permissive `umask` could make the token readable by other local users. Because the path is predictable, another local user may also attempt to create the cache path or a symbolic link before the script writes to it. If the operating system does not block the operation through protections such as `fs.protected_symlinks` or `fs.protected_regular`, a more privileged invocation may follow the attacker-controlled path. The cached value is an application bearer token. It is not merely operational metadata and should be protected to the same degree as other credentials. ### Attack Path 1. A local attacker predicts the fixed cache path `/tmp/feishu_app_token.cache`. 2. The attacker either monitors the path for a permissively created file or pre-creates the path as a regular file or symbolic link. 3. A user or privileged autom ...[truncated 1024 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/upload-image.sh:7
Finding

Python Code Injection Through the OPENCLAW_JSON Environment Variable

Content
View full analysis
Remediation
View remediation
&2 return 1 ;; esac python3 - "$OPENCLAW_JSON" "$1" <<'PY' import json import sys path = sys.argv[1] field = sys.argv[2] with open(path, encoding="utf-8") as config_file: data = json.load(config_file) print(data["channels"]["feishu"][field]) PY } ``` Additional hardening should include: 1. Validate that the configuration path points to an expected regular file. 2. Check file ownership and reject configuration files writable by untrusted users. 3. Use an allowlist for credential field names. 4. For privileged or automated invocation, construct a clean environment rather than inheriting untrusted environment variables. 5. Return a controlled error without exposing credential values or full sensitive API responses. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/upload-image.sh (reported line 45)May include surrounding context.

sh
fi
    fi
    
    local RESP=$(curl -s -X POST "$API_BASE/auth/v3/app_access_token/internal" \
        -H "Content-Type: application/json" \
        -d "{\"app_id\":\"$APP_ID\",\"app_secret\":\"$APP_SECRET\"}")

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/upload-image.sh (reported line 64)May include surrounding context.

sh
# ── Upload ───────────────────────────────────────────────────
APP_TOKEN=$(get_app_token) || exit 1

RESP=$(curl -s -X POST "$API_BASE/im/v1/images" \
    -H "Authorization: Bearer $APP_TOKEN" \
    -F "image_type=message" \
    -F "image=@$IMAGE_PATH;type=image/png")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a shell script but does not declare any tool scope such as allowed-tools or permissions, which weakens least-privilege controls and makes the skill's execution surface implicit rather than explicit. In a system that relies on metadata for policy enforcement or user review, this can allow shell execution where reviewers or orchestrators do not expect it.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script implicitly reads Feishu credentials from a local secrets file even though the skill description only says it uploads a local image and returns an image_key. This creates hidden secret access and couples the skill to broader local credentials, which increases the blast radius if the skill is invoked unexpectedly or in a less-trusted context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/upload-image.sh (reported line 45)May include surrounding context.

sh
fi
    fi
    
    local RESP=$(curl -s -X POST "$API_BASE/auth/v3/app_access_token/internal" \
        -H "Content-Type: application/json" \
        -d "{\"app_id\":\"$APP_ID\",\"app_secret\":\"$APP_SECRET\"}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The app access token is written to a predictable path under /tmp, which is commonly shared across users and processes. Without restrictive file permissions and safer creation semantics, other local users or processes may read, overwrite, or race the cache file, exposing a bearer token that can be reused against the Feishu API until expiry.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script sends the specified image to the Feishu service over HTTP, which is a network operation transmitting user data externally. Although the filename and top comment imply upload behavior, there is no explicit warning, confirmation, or runtime notice informing the user that local file contents are being sent to a third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill documents FEISHU_APP_ID and FEISHU_APP_SECRET environment variable overrides without warning users that these values are secrets that should not be logged, echoed, or committed to shell history or configuration files. This increases the chance of accidental credential disclosure during setup or debugging, especially because the skill is designed to run via shell commands.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.