T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:32- Finding
Hardcoded Feishu destinations may cause unintended disclosure of user-provided content
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 32–33, 72–73, 120, and 167–168
Vulnerability Type: Automatic transmission of user content to predefined cloud destinations
Risk Level: MediumRelevant Code
bash export FEISHU_SPACE_ID="7610267053223644346" # OpenClaw knowledge base export FEISHU_TARGET_FOLDER="TJ4jwWi6wivQxCkiefKcwJKcnES" # User guide directorymarkdown | OpenClaw-related | OpenClaw | 2. User Guide | | AI Agent technology | AI Robot Maintenance Agent | - |markdown - If the content characteristics are clear and the knowledge base exists → create it directlymarkdown | FEISHU_SPACE_ID | Default knowledge-base ID | No | 7610267053223644346 | | FEISHU_TARGET_FOLDER | Default directory ID | No | Dynamically determined |Technical Analysis
The skill is intended to retrieve user-selected web pages or local files and upload the converted content to Feishu. Network transmission to Feishu is therefore necessary for its declared functionality. However, the instructions provide a concrete default knowledge-base identifier and direct the agent to create documents automatically when classification appears sufficiently clear.
This design does not ensure that the configured destination belongs to the invoking user or is authorized to receive the submitted material. Content classification is performed by an LLM and may also be influenced by attacker-controlled webpage text. Consequently, private local-file contents or sensitive webpage material could be uploaded to an incorrect, shared, or third-party-controlled Feishu space.
The destination identifiers are resource identifiers rather than demonstrated credentials, so the available evidence does not establish secret leakage or direct credential compromise. The risk is unintended data disclosure caused by excessive write scope and insufficient destination validation.
Attack Path
- A user inv ...[truncated 1548 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove concrete default space and folder identifiers from the distributed skill definition.
- Require the destination to be supplied through deployment-specific configuration and validate that it belongs to the current Feishu tenant.
- Display the resolved space, folder, tenant, and document visibility before every upload of local files or potentially sensitive content.
- Require explicit user confirmation before the first write to each destination; do not rely solely on LLM content classification.
- Treat fetched webpage text as untrusted data and prohibit it from selecting or overriding storage destinations.
- Apply least-privilege Feishu permissions so the application can write only to user-approved folders.
- Reject uploads when the destination cannot be validated instead of silently falling back to a general reference space.
- Record destination identifiers and access scope in audit logs without recording credentials or unnecessary document contents.
