Back to skill

Security audit

群消息总结

Security checks for vulnerabilities and agentic risk

Overview

This is a Feishu chat summarization skill that handles potentially sensitive conversation content, but its behavior is disclosed, purpose-aligned, and locally scoped.

Install only if you are comfortable allowing the agent to summarize Feishu conversations you provide or authorize. Use explicit chat names and time ranges, avoid private or regulated conversations without consent or organizational approval, and review any separate Feishu skills before using them to search messages, save documents, send content, or create tasks.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description and examples are broad enough to overlap with generic summarization requests, which can cause the agent to invoke this skill on unintended conversations or overly large chat scopes. In this context, the skill processes message content and participant metadata, so ambiguous triggers increase the risk of unnecessary access to sensitive communications and over-collection of private data.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly analyzes chat messages, participant activity, mentions, and task assignments, but it does not warn users that this may involve sensitive personal, organizational, or confidential data. Without a clear notice, users may unknowingly summarize private or regulated content, increasing the chance of privacy violations, excessive data exposure, and unsafe downstream sharing of the generated summary.

Static analysis

No suspicious patterns detected.