Back to skill

Security audit

让飞书可以发图片消息

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it claims, but its remote-image feature can fetch arbitrary URLs from the host and forward the result to Feishu.

Review before installing. Use this only with a minimally permissioned Feishu app, do not pass untrusted or internal URLs, and avoid sending sensitive screenshots, personal data, signed links, or confidential files. Prefer running it from a restricted network environment and be aware that short-lived bearer tokens may appear in local process listings while scripts run.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/send_image.sh:55
Finding

Unrestricted Remote Image Retrieval Enables SSRF and Internal Data Forwarding

Content
View full analysis
&2 TEMP_FILE=$(mktemp /tmp/feishu_image.XXXXXX) curl -s -o "$TEMP_FILE" "$IMAGE_INPUT" if [[ ! -s "$TEMP_FILE" ]]; then echo "Error: Failed to download image from URL" >&2 rm -f "$TEMP_FILE" exit 1 fi IMAGE_FILE="$TEMP_FILE" echo "Image downloaded to: $IMAGE_FILE" >&2 else # Use local file IMAGE_FILE="$IMAGE_INPUT" if [[ ! -f "$IMAGE_FILE" ]]; then echo "Error: Image file not found: $IMAGE_FILE" >&2 exit 1 fi echo "Step 2: Using local image file" >&2 fi # Step 3: Upload image echo "Step 3: Uploading image to Feishu..." >&2 IMAGE_KEY=$("${SCRIPT_DIR}/upload_image.sh" -f "$IMAGE_FILE" -t "$TOKEN") echo "Image uploaded, key: $IMAGE_KEY" >&2 # Cleanup temp file if we downloaded one if [[ -n "${TEMP_FILE:-}" && -f "$TEMP_FILE" ]]; then rm -f "$TEMP_FILE" fi # Step 4: Send message echo "Step 4: Sending message..." >&2 MESSAGE_ID=$("${SCRIPT_DIR}/send_message.sh" -r "$RECEIVE_ID" -k "$IMAGE_KEY" -t "$TEXT" -a "$TOKEN") ``` ### Technical Analysis The script accepts an arbitrary HTTP or HTTPS URL through `IMAGE_INPUT` and passes it directly to `curl`. It does not validate the destination hostname or resolved IP address and does not reject loopback, link-local, private-network, or other reserved destinations. Consequently, the script can make network requests using the host's network position. The downloaded response is then uploaded to Feishu and delivered to a caller-selected recipient. This turns the functionality into a potential SSRF and data-forwarding primitive when an untrusted party can influence the script arguments. The download also lacks connection and transfer timeo ...[truncated 2060 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/send_image.sh:79
Finding

Feishu Tenant Access Token Exposed in Process Command-Line Arguments

Content
View full analysis
&2 # Cleanup temp file if we downloaded one if [[ -n "${TEMP_FILE:-}" && -f "$TEMP_FILE" ]]; then rm -f "$TEMP_FILE" fi # Step 4: Send message echo "Step 4: Sending message..." >&2 MESSAGE_ID=$("${SCRIPT_DIR}/send_message.sh" -r "$RECEIVE_ID" -k "$IMAGE_KEY" -t "$TEXT" -a "$TOKEN") ``` `scripts/upload_image.sh:14-17`: ```bash while getopts "f:t:" opt; do case $opt in f) IMAGE_FILE="$OPTARG" ;; t) TOKEN="$OPTARG" ;; ``` `scripts/upload_image.sh:34-36`: ```bash response=$(curl -s -X POST "${FEISHU_IMAGE_UPLOAD_ENDPOINT}" \ -H "Authorization: Bearer ${TOKEN}" \ -F "image=@${IMAGE_FILE}" \ ``` `scripts/send_message.sh:16-21`: ```bash while getopts "r:k:t:a:" opt; do case $opt in r) RECEIVE_ID="$OPTARG" ;; k) IMAGE_KEY="$OPTARG" ;; t) TEXT="$OPTARG" ;; a) TOKEN="$OPTARG" ;; ``` `scripts/send_message.sh:74-76`: ```bash response=$(curl -s -X POST "${FEISHU_MESSAGE_ENDPOINT}?receive_id_type=open_id" \ -H "Authorization: Bearer ${TOKEN}" \ -H "Content-Type: application/json" \ ``` ### Technical Analysis The tenant access token is passed from `send_image.sh` to child scripts through the `-t` and `-a` command-line options. Command-line arguments may be visible through process-inspection interfaces, process listings, monitoring agents, audit systems, debugging tools, or process telemetry, depending on operating-system configuration and user permissions. The token is subsequently interpolated into `curl`'s authorization-header ar ...[truncated 1929 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (22)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
## 注意事项 / Notes

- ⚠️ 请妥善保管 `FEISHU_APP_ID` 和 `FEISHU_APP_SECRET`,不要提交到代码仓库
- 🔄 Access token 有效期为 2 小时,脚本会自动处理获取
- 📤 图片上传后获得的 `image_key` 有效期为 1 年
- 🎯 `image_key` 可以重复使用,建议缓存以减少上传次数

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
## 注意事项 / Notes

- ⚠️ 请妥善保管 `FEISHU_APP_ID` 和 `FEISHU_APP_SECRET`,不要提交到代码仓库
- 🔄 Access token 有效期为 2 小时,脚本会自动处理获取
- 📤 图片上传后获得的 `image_key` 有效期为 1 年
- 🎯 `image_key` 可以重复使用,建议缓存以减少上传次数

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api.md (reported line 67)May include surrounding context.

md
## Authentication APIs

### Get Tenant Access Token
Obtain a tenant access token for API authentication.

**Endpoint:** `POST /open-apis/auth/v3/tenant_access_token/internal`

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api.md (reported line 68)May include surrounding context.

md
## Authentication APIs

### Get Tenant Access Token
Obtain a tenant access token for API authentication.

**Endpoint:** `POST /open-apis/auth/v3/tenant_access_token/internal`

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api.md (reported line 139)May include surrounding context.

md
## Authentication APIs

### Get Tenant Access Token
Obtain a tenant access token for API authentication.

**Endpoint:** `POST /open-apis/auth/v3/tenant_access_token/internal`

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
#!/bin/bash
# Get Feishu tenant access token

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/get_token.sh (reported line 2)May include surrounding context.

sh
#!/bin/bash
# Get Feishu tenant access token

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/send_image.sh (reported line 49)May include surrounding context.

sh
#!/bin/bash
# Get Feishu tenant access token

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/send_image.sh (reported line 50)May include surrounding context.

sh
#!/bin/bash
# Get Feishu tenant access token

set -e

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The script accepts an arbitrary user-supplied URL and fetches it with curl without allowlisting, protocol restrictions, IP range checks, size limits, or timeouts. This can enable SSRF-style behavior from the host running the script, allowing access to internal services or cloud metadata endpoints, and may also permit denial-of-service via large or slow responses.

Content

Scanner excerpt · scripts/send_image.sh (reported line 59)May include surrounding context.

sh
# Download remote image
  echo "Step 2: Downloading remote image..." >&2
  TEMP_FILE=$(mktemp /tmp/feishu_image.XXXXXX)
  curl -s -o "$TEMP_FILE" "$IMAGE_INPUT"
  if [[ ! -s "$TEMP_FILE" ]]; then
    echo "Error: Failed to download image from URL" >&2
    rm -f "$TEMP_FILE"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and instructs shell-script execution (./scripts/*.sh) but does not declare any tool scope such as permissions or allowed-tools. This creates an authorization and review gap: users or platforms cannot clearly understand that shell execution is required, increasing the chance of unintended command execution in environments with broader privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage section encourages sending local images, remote image URLs, and text to Feishu, but does not clearly warn that this data will be transmitted to a third-party service and may include sensitive information. This can lead users to unintentionally exfiltrate confidential screenshots, report images, URLs containing secrets, or message content outside their trust boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document explains how to upload images and send messages to Feishu but does not disclose the privacy-impacting behavior that files and message contents leave the local environment and are stored or processed by an external platform. For markdown skills or references, this kind of data-transfer behavior should be explicitly warned about.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents use of a tenant access token and later an app secret for external API calls to Feishu, which can affect privacy and account security if mishandled. Under the markdown-file criteria, the description should warn users that credentials and message/image data are sent to a third-party service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
76% confidence
Finding

The script posts FEISHU_APP_ID and FEISHU_APP_SECRET to a configurable endpoint loaded from config.sh, and it does not verify that the endpoint is the legitimate Feishu domain. If an attacker can alter configuration or package contents, the script could silently exfiltrate credentials to an attacker-controlled server.

Content

Scanner excerpt · scripts/get_token.sh (reported line 11)May include surrounding context.

sh
source "${SCRIPT_DIR}/config.sh"

# Get token from Feishu API
response=$(curl -s -X POST "${FEISHU_AUTH_ENDPOINT}" \
  -H "Content-Type: application/json" \
  -d "{
    \"app_id\": \"${FEISHU_APP_ID}\",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script sends FEISHU_APP_ID and FEISHU_APP_SECRET in an HTTP POST request to obtain a tenant access token. While the comments describe the technical purpose, there is no user-facing warning, prompt, or explicit disclosure about transmitting credentials over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The payload uses the fixed locale key "zh_cn" and Chinese titles, which forces a specific language/locale in the generated message content. There is no indication in the script that users can opt into another language or that the locale restriction is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

In the image-only branch, the script again fixes the content locale to "zh_cn" with a Chinese title, enforcing a specific language choice regardless of user preference. This matches the policy concern for forced language or locale without opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/send_message.sh (reported line 74)May include surrounding context.

sh
}')

# Send message
response=$(curl -s -X POST "${FEISHU_MESSAGE_ENDPOINT}?receive_id_type=open_id" \
  -H "Authorization: Bearer ${TOKEN}" \
  -H "Content-Type: application/json" \
  -d "$request_body")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs a network POST to the Feishu API containing the recipient ID, message content, and authorization token, but the script provides no confirmation prompt and no user-facing notice before transmission. Aside from a brief header comment, there is no explicit disclosure in the script output warning that supplied text and identifiers will be sent to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file presents the skill description primarily in Chinese, with only partial English support, but does not state any language-selection behavior or limitation. Per the policy, forcing or assuming a specific language without user opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example post content structure uses only the zh_cn locale and Chinese text, which can amount to a language/locale policy issue when presented as the default format without opt-in or alternatives. The file does not indicate that the locale is merely illustrative or provide other language options.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.