T09 · Insecure Skill Coding Practices
- Location
tools.py:28- Finding
Customer PII Is Transmitted Without Enforced Confirmation or Data Masking
- Content
View full analysis
Vulnerability Details
File Location:
tools.py:28-88
Related Documentation:README.md:7-10,README.md:37-39
Vulnerability Type: Missing consent enforcement and unimplemented privacy controls
Risk Level: MediumComplete Code Snippet
python def submit_to_feishu( name: str, phone: str, destination: str, people_count: int, departure_date: Optional[str] = "", budget: Optional[float] = 0.0, preferences: Optional[List[str]] = None, special_requirements: Optional[str] = "" ) -> Dict[str, Any]: """ ClawHub tool function: submits travel requirements to a Feishu multidimensional table. """ app_id = os.getenv("FEISHU_APP_ID") app_secret = os.getenv("FEISHU_APP_SECRET") base_token = os.getenv("FEISHU_BASE_TOKEN") table_id = os.getenv("FEISHU_TABLE_ID") missing_configs = [] if not app_id: missing_configs.append("FEISHU_APP_ID") if not app_secret: missing_configs.append("FEISHU_APP_SECRET") if not base_token: missing_configs.append("FEISHU_BASE_TOKEN") if not table_id: missing_configs.append("FEISHU_TABLE_ID") if missing_configs: return { "status": "error", "message": f"Missing Skill configuration: {', '.join(missing_configs)}" } try: token = get_tenant_access_token(app_id, app_secret) fields = { "Name": name, "Contact phone": phone, "Intended destination": destination, "Number of travelers": people_count } if departure_date: fields["Expected departure date"] = departure_date if budget and budget > 0: fields["Budget per person"] = budget if preferences and len(preferences) > 0: fields["Travel preferences"] = preferences if special_requirements: fields["Special r ...[truncated 3011 chars]- Remediation
View remediation
Remediation Suggestions
- Add an explicit confirmation parameter backed by trusted agent state, rather than relying only on natural-language instructions:
python if confirmed is not True: return { "status": "confirmation_required", "message": "Explicit user confirmation is required before submission." } - Do not allow prompt-controlled text alone to manufacture the confirmation state. The orchestration layer should set it only after presenting the exact data and receiving an affirmative response.
- Mask telephone numbers in conversational output and logs. If the complete number is operationally necessary in Feishu, clearly disclose that it will be stored unmasked.
- Collect only fields required for the stated business purpose. Make optional fields opt-in and warn users before accepting sensitive details in
special_requirements. - Add type, length, and format validation for phone numbers, dates, traveler counts, budgets, preferences, and free-form text.
- Document the destination, intended recipients, retention period, deletion process, and whether the Feishu table is shared with third parties.
- Restrict the Feishu application and table collaborators to the minimum roles required to create and process these records.
- Either implement the README’s claimed masking behavior or remove the claim so users are not given an inaccurate privacy assurance.
- Add an explicit confirmation parameter backed by trusted agent state, rather than relying only on natural-language instructions:
