T09 · Insecure Skill Coding Practices
- Location
scripts/feishu_calendar.sh:138- Finding
Arbitrary Python Code Execution Through Unsafe Argument Interpolation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This MBTI coaching skill is coherent overall, but its Feishu/Lark calendar helper has unsafe credential handling and command construction that should be reviewed before installation.
Install only if you are comfortable with a skill storing a local personality profile and, when calendar features are used, sending scheduling data to Feishu/Lark. Before using the calendar helper, remove or restrict the token command, avoid sourcing untrusted .env files, fix the unsafe python3 -c interpolation, and make the external-sharing behavior explicit.
scripts/feishu_calendar.sh:138Arbitrary Python Code Execution Through Unsafe Argument Interpolation
scripts/feishu_calendar.sh:178Live Feishu Access Token Exposed Through Debug Command
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
**Developing Ne (Extraverted Intuition):**
- Generate 10 wildly different solutions to one problem (no filtering)
- Connect two unrelated ideas and find a real application
- Challenge: Brainstorm for 15 minutes without judging any idea
**Developing Ni (Introverted Intuition):**
- Sit with one question for 20 minutes without looking anything up
The documented capability to print an access token indicates the script intentionally exposes a sensitive credential to the caller. In an agent skill context, even documented secret output is dangerous because outputs may be copied into logs, chat history, or other systems outside the user's control.
# 用法:
# feishu_calendar.sh list [days] 列出未来 N 天的事件(默认7天)
# feishu_calendar.sh create TITLE START END [DESC] 创建事件
# feishu_calendar.sh token 获取并打印 access token(调试用)
set -e
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
return 0
fi
fi
# 3. skill 目录下的 .env
local skill_dir
skill_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
local env_file="$skill_dir/.env"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
return 0
fi
fi
# 3. skill 目录下的 .env
local skill_dir
skill_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
local env_file="$skill_dir/.env"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
return 0
fi
fi
# 3. skill 目录下的 .env
local skill_dir
skill_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
local env_file="$skill_dir/.env"
Sourcing .env with source "$env_file" executes the file as shell code, not merely parses key/value pairs. If an attacker can modify the skill directory or place a malicious .env, arbitrary commands will run with the privileges of the script, which is especially risky in agent or shared workspace environments.
# 3. skill 目录下的 .env
local skill_dir
skill_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
local env_file="$skill_dir/.env"
if [[ -f "$env_file" ]]; then
# shellcheck disable=SC1090
source "$env_file"
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
_get_token() {
_load_credentials
local resp
resp=$(curl -s -X POST "$FEISHU_BASE/auth/v3/tenant_access_token/internal" \
-H "Content-Type: application/json" \
-d "{\"app_id\":\"$FEISHU_APP_ID\",\"app_secret\":\"$FEISHU_APP_SECRET\"}")
local code
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
return
fi
local resp
resp=$(curl -s "$FEISHU_BASE/calendar/v4/calendars" \
-H "Authorization: Bearer $token")
# 找 primary 日历
echo "$resp" | python3 -c "
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
end_ts=$((now + days * 86400))
local resp
resp=$(curl -s "$FEISHU_BASE/calendar/v4/calendars/$cal_id/events?start_time=$now&end_time=$end_ts&page_size=50" \
-H "Authorization: Bearer $token")
echo "$resp" | python3 -c "
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
")
local resp
resp=$(curl -s -X POST "$FEISHU_BASE/calendar/v4/calendars/$cal_id/events" \
-H "Authorization: Bearer $token" \
-H "Content-Type: application/json" \
-d "$payload")
Broad trigger keywords like 'MBTI', '安排日程', or '查看进度' can cause the skill to activate in unintended contexts, potentially exposing profile data, initiating coaching flows, or invoking integrations without clear user intent. In an agent environment, overbroad activation increases the chance of accidental execution and unintended handling of personal data.
The README makes an absolute privacy claim that 'Nothing is shared externally,' yet earlier sections describe optional Feishu/Lark calendar integration and instruct users to configure external-service credentials. This mismatch can mislead users into granting sensitive profile or scheduling data under false assumptions, undermining informed consent and privacy expectations.
The trigger phrases include very broad language such as 'personality coach', 'I want to become', and 'check my progress', which can overlap with ordinary conversation and cause accidental invocation. Unintended activation is especially risky here because the skill persists sensitive personality-profile data and may steer users into data collection flows without clear intent.
The skill instructs reading and saving a persistent profile containing MBTI type, historical types, cognitive scores, stress signals, and session counts, but it does not tell the user that this sensitive psychological-profile data will be stored. This creates a privacy and consent issue because users may disclose intimate personal information without understanding retention or access implications.
The skill includes a Feishu/Lark calendar automation step and references external credentials in .env, but no explicit permission model, scope limitation, or user-consent flow is defined. In a coaching skill that handles sensitive personality and habit data, this can lead to unintended transmission of scheduling or behavioral information to a third-party service.
The calendar integration sends scheduling details to a third-party service using external credentials, but the skill does not warn the user that their exercise plans and timestamps may leave the local environment. For a personality-coaching skill, these entries can reveal behavioral goals and sensitive self-improvement patterns.
The documented token command prints a live tenant access token directly to stdout, which can be captured in terminal scrollback, shell history wrappers, logs, CI output, or by other local tooling. Although described as debug-only, the token is reusable for authenticated Feishu API access during its validity window, so exposing it materially increases credential leakage risk.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
_get_token() {
_load_credentials
local resp
resp=$(curl -s -X POST "$FEISHU_BASE/auth/v3/tenant_access_token/internal" \
-H "Content-Type: application/json" \
-d "{\"app_id\":\"$FEISHU_APP_ID\",\"app_secret\":\"$FEISHU_APP_SECRET\"}")
local code
The created event payload forces timezone to Asia/Shanghai for all users. This is a locale policy issue because the script does not offer opt-in, configuration, or documentation that it is intended only for a China-specific deployment.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
")
local resp
resp=$(curl -s -X POST "$FEISHU_BASE/calendar/v4/calendars/$cal_id/events" \
-H "Authorization: Bearer $token" \
-H "Content-Type: application/json" \
-d "$payload")
cmd_token() invokes _get_token and emits the bearer token with no warning, redaction, or confirmation prompt. In a skill context, this is more dangerous because agent users may invoke helper commands indirectly and secrets can be surfaced into chat transcripts, orchestration logs, or monitoring systems.
The module docstring and all user-facing messages in the script are written in Chinese, indicating the skill forces a specific language for interaction. Under the policy, locale constraints should either be optional for the user or clearly documented as a justified region-specific limitation.
The invocation description is vague about what exact phrase or condition activates the skill, which can lead to inconsistent or unintended invocation in a multi-skill agent environment. While not directly exploitable like code execution, ambiguous activation logic increases the risk of accidental processing of sensitive self-assessment data.
No suspicious patterns detected.