T09 · Insecure Skill Coding Practices
- Location
tools.py:87- Finding
Feishu resource identifiers exposed through unsanitized exception messages
- Content
View full analysis
Vulnerability Details
File Location:
tools.py, lines 87–104
Vulnerability Type: Sensitive information exposure through verbose error handling
Risk Level: MediumVulnerable Code:
python url = f"{FEISHU_API_BASE}/bitable/v1/apps/{base_token}/tables/{table_id}/records" headers = { "Authorization": f"Bearer {token}", "Content-Type": "application/json" } payload = { "records": [{"fields": fields}] } resp = requests.post(url, headers=headers, json=payload, timeout=10) resp.raise_for_status() result = resp.json() if result.get('code') == 0: return {"status": "success", "message": "需求已成功提交至飞书表格!"} else: return {"status": "error", "message": f"飞书 API 错误: {result.get('msg')}"} except Exception as e: return {"status": "error", "message": f"系统异常: {str(e)}"}Technical Analysis
The request URL embeds the configured
FEISHU_BASE_TOKENandFEISHU_TABLE_ID. When Feishu returns a non-successful HTTP status,requests.Response.raise_for_status()raises an exception whose text can include the request URL. The catch-all exception handler then returns that raw exception text to the tool caller.Consequently, an internal integration error can disclose Feishu resource identifiers beyond the trusted server boundary. The bearer token is placed in an HTTP header and is not ordinarily included in
raise_for_status()output, and the application secret is only used by the separate authentication request. Therefore, the reviewed path does not establish direct disclosure of the bearer token or application secret.The fixed official HTTPS endpoint prevents caller-controlled server-side request forgery. Sending the credentials and traveler information to Feishu is otherwise consistent with the Skill's declared purpose.
Attack Path
- An attacker or untrusted user invokes the submission tool after satisfying the conversational confirmation workflow.
- The reque ...[truncated 929 chars]
- Remediation
View remediation
Remediation Suggestions
- Never return raw exception strings from HTTP libraries to users or agent-visible tool responses.
- Return a fixed, generic failure message with a non-sensitive internal error code.
- Record detailed diagnostics only in access-controlled server logs.
- Sanitize logged URLs by replacing the Base Token and Table ID path segments with placeholders.
- Do not log authorization headers, application secrets, tenant access tokens, request bodies containing traveler data, or complete remote responses.
- Catch narrower exception classes such as
requests.Timeout,requests.ConnectionError, andrequests.HTTPError. - Validate Feishu responses while retaining only safe fields such as a documented error code.
- Add tests that trigger non-2xx responses and verify that returned errors contain no configured identifiers, credentials, URLs, headers, or traveler data.
