Back to skill

Security audit

MBTI Coach — Personality Development System

Security checks for vulnerabilities and agentic risk

Overview

This MBTI coaching skill is coherent overall, but its Feishu/Lark calendar helper has unsafe credential handling and command construction that should be reviewed before installation.

Install only if you are comfortable with a skill storing a local personality profile and, when calendar features are used, sending scheduling data to Feishu/Lark. Before using the calendar helper, remove or restrict the token command, avoid sourcing untrusted .env files, fix the unsafe python3 -c interpolation, and make the external-sharing behavior explicit.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/feishu_calendar.sh:138
Finding

Arbitrary Python Code Execution Through Unsafe Argument Interpolation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/feishu_calendar.sh:178
Finding

Live Feishu Access Token Exposed Through Debug Command

Content
View full analysis
[arguments]" exit 1 ;; esac ``` The called function returns the raw token to standard output: ```bash echo "$resp" | python3 -c "import json,sys; print(json.load(sys.stdin)['tenant_access_token'])" ``` ### Technical Analysis The public `token` subcommand invokes `_get_token`, which authenticates with the configured Feishu application ID and secret and prints the resulting tenant access token in full to standard output. Standard output from an Agent-executed tool may be retained in conversation transcripts, command logs, CI logs, terminal scrollback, telemetry, or error reports. Access tokens are bearer credentials: possession may be sufficient to perform API operations authorized by the associated Feishu application until the token expires or is revoked. Printing a live credential is unnecessary for the Skill's declared calendar listing and event creation functionality. Internal commands can consume the token without exposing it to users or logs. ### Attack Path 1. An attacker, untrusted user, or injected instruction asks the Agent to run: ```bash bash scripts/feishu_calendar.sh token ``` 2. The script reads the configured Feishu application credentials. 3. It exchanges those credentials for a tenant access token. 4. The complete bearer token is printed to standard output. 5. The output is displayed to the requesting party or retained in accessible log ...[truncated 833 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (23)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
**Developing Ne (Extraverted Intuition):**
- Generate 10 wildly different solutions to one problem (no filtering)
- Connect two unrelated ideas and find a real application
- Challenge: Brainstorm for 15 minutes without judging any idea

**Developing Ni (Introverted Intuition):**
- Sit with one question for 20 minutes without looking anything up

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The documented capability to print an access token indicates the script intentionally exposes a sensitive credential to the caller. In an agent skill context, even documented secret output is dangerous because outputs may be copied into logs, chat history, or other systems outside the user's control.

Content

Scanner excerpt · scripts/feishu_calendar.sh (reported line 6)May include surrounding context.

sh
# 用法:
#   feishu_calendar.sh list [days]          列出未来 N 天的事件(默认7天)
#   feishu_calendar.sh create TITLE START END [DESC]  创建事件
#   feishu_calendar.sh token                获取并打印 access token(调试用)

set -e

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 69)May include surrounding context.

md
return 0
    fi
  fi
  # 3. skill 目录下的 .env
  local skill_dir
  skill_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
  local env_file="$skill_dir/.env"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 70)May include surrounding context.

md
return 0
    fi
  fi
  # 3. skill 目录下的 .env
  local skill_dir
  skill_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
  local env_file="$skill_dir/.env"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/feishu_calendar.sh (reported line 28)May include surrounding context.

sh
return 0
    fi
  fi
  # 3. skill 目录下的 .env
  local skill_dir
  skill_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
  local env_file="$skill_dir/.env"

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

Sourcing .env with source "$env_file" executes the file as shell code, not merely parses key/value pairs. If an attacker can modify the skill directory or place a malicious .env, arbitrary commands will run with the privileges of the script, which is especially risky in agent or shared workspace environments.

Content

Scanner excerpt · scripts/feishu_calendar.sh (reported line 31)May include surrounding context.

sh
# 3. skill 目录下的 .env
  local skill_dir
  skill_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
  local env_file="$skill_dir/.env"
  if [[ -f "$env_file" ]]; then
    # shellcheck disable=SC1090
    source "$env_file"

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/feishu_calendar.sh (reported line 45)May include surrounding context.

sh
_get_token() {
  _load_credentials
  local resp
  resp=$(curl -s -X POST "$FEISHU_BASE/auth/v3/tenant_access_token/internal" \
    -H "Content-Type: application/json" \
    -d "{\"app_id\":\"$FEISHU_APP_ID\",\"app_secret\":\"$FEISHU_APP_SECRET\"}")
  local code

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/feishu_calendar.sh (reported line 65)May include surrounding context.

sh
return
  fi
  local resp
  resp=$(curl -s "$FEISHU_BASE/calendar/v4/calendars" \
    -H "Authorization: Bearer $token")
  # 找 primary 日历
  echo "$resp" | python3 -c "

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/feishu_calendar.sh (reported line 101)May include surrounding context.

sh
end_ts=$((now + days * 86400))

  local resp
  resp=$(curl -s "$FEISHU_BASE/calendar/v4/calendars/$cal_id/events?start_time=$now&end_time=$end_ts&page_size=50" \
    -H "Authorization: Bearer $token")

  echo "$resp" | python3 -c "

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/feishu_calendar.sh (reported line 160)May include surrounding context.

sh
")

  local resp
  resp=$(curl -s -X POST "$FEISHU_BASE/calendar/v4/calendars/$cal_id/events" \
    -H "Authorization: Bearer $token" \
    -H "Content-Type: application/json" \
    -d "$payload")

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Broad trigger keywords like 'MBTI', '安排日程', or '查看进度' can cause the skill to activate in unintended contexts, potentially exposing profile data, initiating coaching flows, or invoking integrations without clear user intent. In an agent environment, overbroad activation increases the chance of accidental execution and unintended handling of personal data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README makes an absolute privacy claim that 'Nothing is shared externally,' yet earlier sections describe optional Feishu/Lark calendar integration and instruct users to configure external-service credentials. This mismatch can mislead users into granting sensitive profile or scheduling data under false assumptions, undermining informed consent and privacy expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases include very broad language such as 'personality coach', 'I want to become', and 'check my progress', which can overlap with ordinary conversation and cause accidental invocation. Unintended activation is especially risky here because the skill persists sensitive personality-profile data and may steer users into data collection flows without clear intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs reading and saving a persistent profile containing MBTI type, historical types, cognitive scores, stress signals, and session counts, but it does not tell the user that this sensitive psychological-profile data will be stored. This creates a privacy and consent issue because users may disclose intimate personal information without understanding retention or access implications.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill includes a Feishu/Lark calendar automation step and references external credentials in .env, but no explicit permission model, scope limitation, or user-consent flow is defined. In a coaching skill that handles sensitive personality and habit data, this can lead to unintended transmission of scheduling or behavioral information to a third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The calendar integration sends scheduling details to a third-party service using external credentials, but the skill does not warn the user that their exercise plans and timestamps may leave the local environment. For a personality-coaching skill, these entries can reveal behavioral goals and sensitive self-improvement patterns.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented token command prints a live tenant access token directly to stdout, which can be captured in terminal scrollback, shell history wrappers, logs, CI output, or by other local tooling. Although described as debug-only, the token is reusable for authenticated Feishu API access during its validity window, so exposing it materially increases credential leakage risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/feishu_calendar.sh (reported line 45)May include surrounding context.

sh
_get_token() {
  _load_credentials
  local resp
  resp=$(curl -s -X POST "$FEISHU_BASE/auth/v3/tenant_access_token/internal" \
    -H "Content-Type: application/json" \
    -d "{\"app_id\":\"$FEISHU_APP_ID\",\"app_secret\":\"$FEISHU_APP_SECRET\"}")
  local code

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The created event payload forces timezone to Asia/Shanghai for all users. This is a locale policy issue because the script does not offer opt-in, configuration, or documentation that it is intended only for a China-specific deployment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/feishu_calendar.sh (reported line 160)May include surrounding context.

sh
")

  local resp
  resp=$(curl -s -X POST "$FEISHU_BASE/calendar/v4/calendars/$cal_id/events" \
    -H "Authorization: Bearer $token" \
    -H "Content-Type: application/json" \
    -d "$payload")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

cmd_token() invokes _get_token and emits the bearer token with no warning, redaction, or confirmation prompt. In a skill context, this is more dangerous because agent users may invoke helper commands indirectly and secrets can be surfaced into chat transcripts, orchestration logs, or monitoring systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring and all user-facing messages in the script are written in Chinese, indicating the skill forces a specific language for interaction. Under the policy, locale constraints should either be optional for the user or clearly documented as a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation description is vague about what exact phrase or condition activates the skill, which can lead to inconsistent or unintended invocation in a multi-skill agent environment. While not directly exploitable like code execution, ambiguous activation logic increases the risk of accidental processing of sensitive self-assessment data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.