Back to skill

Security audit

网页转飞书文档 Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but it can upload arbitrary user-provided web or local-file content into Feishu using broad default destinations and sometimes without explicit destination confirmation.

Review the configured Feishu space and folder before use, especially for private URLs or local files. Use this skill only with content you are comfortable storing in the configured Feishu workspace, and prefer requiring explicit confirmation of the destination before each upload.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:32
Finding

Hardcoded Feishu destinations may cause unintended disclosure of user-provided content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 32–33, 72–73, 120, and 167–168
Vulnerability Type: Automatic transmission of user content to predefined cloud destinations
Risk Level: Medium

Relevant Code

bash
export FEISHU_SPACE_ID="7610267053223644346"  # OpenClaw knowledge base
export FEISHU_TARGET_FOLDER="TJ4jwWi6wivQxCkiefKcwJKcnES"  # User guide directory
markdown
| OpenClaw-related | OpenClaw | 2. User Guide |
| AI Agent technology | AI Robot Maintenance Agent | - |
markdown
- If the content characteristics are clear and the knowledge base exists → create it directly
markdown
| FEISHU_SPACE_ID | Default knowledge-base ID | No | 7610267053223644346 |
| FEISHU_TARGET_FOLDER | Default directory ID | No | Dynamically determined |

Technical Analysis

The skill is intended to retrieve user-selected web pages or local files and upload the converted content to Feishu. Network transmission to Feishu is therefore necessary for its declared functionality. However, the instructions provide a concrete default knowledge-base identifier and direct the agent to create documents automatically when classification appears sufficiently clear.

This design does not ensure that the configured destination belongs to the invoking user or is authorized to receive the submitted material. Content classification is performed by an LLM and may also be influenced by attacker-controlled webpage text. Consequently, private local-file contents or sensitive webpage material could be uploaded to an incorrect, shared, or third-party-controlled Feishu space.

The destination identifiers are resource identifiers rather than demonstrated credentials, so the available evidence does not establish secret leakage or direct credential compromise. The risk is unintended data disclosure caused by excessive write scope and insufficient destination validation.

Attack Path

  1. A user inv ...[truncated 1548 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove concrete default space and folder identifiers from the distributed skill definition.
  2. Require the destination to be supplied through deployment-specific configuration and validate that it belongs to the current Feishu tenant.
  3. Display the resolved space, folder, tenant, and document visibility before every upload of local files or potentially sensitive content.
  4. Require explicit user confirmation before the first write to each destination; do not rely solely on LLM content classification.
  5. Treat fetched webpage text as untrusted data and prohibit it from selecting or overriding storage destinations.
  6. Apply least-privilege Feishu permissions so the application can write only to user-approved folders.
  7. Reject uploads when the destination cannot be validated instead of silently falling back to a general reference space.
  8. Record destination identifiers and access scope in audit logs without recording credentials or unnecessary document contents.

T01 · Skill Instruction Hijacking

Note
Location
SKILL.md:90
Finding

Skill-enforced attribution modifies generated documents without a demonstrated functional requirement

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 90
Vulnerability Type: Predetermined output-content modification
Risk Level: Low

Relevant Code

markdown
> Compiled by: Xiaowan AI

Technical Analysis

The document template requires every generated document to contain a fixed attribution string. This text is unrelated to converting the source material into structured Markdown or saving it to Feishu. It therefore alters user-visible output beyond the minimum behavior needed for the declared functionality.

The instruction does not override system safety constraints, execute code, retrieve a remote payload, or grant additional permissions. Its effect is limited to inserting branding into generated documents. Accordingly, it represents a low-impact form of output manipulation rather than a conventional compromise of the agent session.

Attack Path

  1. A user asks the skill to convert and save a page or local file.
  2. The agent follows the mandatory document template.
  3. The generated Feishu document includes the fixed attribution even if the user did not request it.
  4. Readers may incorrectly infer that the named party created, reviewed, or endorsed the document.

No path to code execution, credential theft, persistence, or elevated system access is demonstrated.

Impact Assessment

The impact is limited to document integrity, attribution accuracy, and potential reputational or provenance confusion. The instruction obtains no additional system or Feishu privileges and does not expand access to user data beyond the upload behavior addressed separately.

Remediation
View remediation

Remediation Suggestions

  1. Remove the fixed attribution from the default template.
  2. Include attribution only when explicitly requested or configured by the user or deploying organization.
  3. Clearly distinguish source authorship, automated conversion, and human review.
  4. Keep the generated document faithful to the source and avoid adding endorsements or identities that are not necessary for conversion.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes generic phrases like '转文档' and '保存网页', which are broad enough to match ordinary conversation and unintentionally activate a workflow that fetches external content and writes to Feishu. Because the skill performs network retrieval and cloud document creation, accidental activation can cause unintended data processing or document creation without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes broad support for arbitrary URLs and local files but does not clearly warn users up front that the content will be sent to external retrieval tools and then written into Feishu cloud documents. This reduces informed consent and can mislead users into sharing links or files containing confidential, copyrighted, or personal data without understanding the external processing and persistence involved.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The activation condition applies to any URL or local file whenever a user asks to convert or save it, with no scope restriction on sensitive, internal, or unsupported sources. In this context, the skill can ingest arbitrary local files or remote content and transfer the resulting content into external tools and Feishu, increasing the risk of unintended disclosure, over-collection, or processing of sensitive material.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.