Back to skill

Security audit

Bot Roundtable

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Feishu multi-bot discussion helper, but its automatic broad triggers and group-posting behavior need careful review before use.

Review this before installing in any real Feishu group. Only enable it in chats where participants expect automated multi-bot replies, use explicit command-style triggers if possible, restrict who can invoke it, and clarify exactly where bot credentials are stored.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documentation and invocation examples are entirely specified in Chinese, including the required trigger phrases, with no indication that users may choose another language or locale. This creates a natural-language policy concern because the skill appears to require a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad, natural-language expressions likely to occur in normal group conversation, which can cause the skill to activate unintentionally. In this skill's context, accidental activation is more dangerous because it can spawn multiple bot personas and send messages into a shared Feishu group, causing spam, confusion, or unauthorized automated responses.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description on L04 is written as a Chinese-only user-facing capability statement and indicates the skill is intended for a Chinese-language Feishu group context, but there is no indication of language choice, opt-in, or documented locale limitation. This can violate language/locale policy when a skill implicitly restricts interaction to one language without making that constraint explicit and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documentation earlier states that bot credentials are configured in config.json and even provides a config.json example, but L75 says credentials are read from openclaw.json under channels.feishu.accounts. These are mutually inconsistent configuration sources, so the documentation actively contradicts itself about where secrets are actually loaded from.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.