Back to skill

Security audit

Solidot 资讯推送

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Solidot-to-Feishu purpose, but it needs review because it handles a Feishu document token unsafely and can write to Feishu or the local workspace.

Review before installing. Use a narrowly scoped Feishu document token, be aware that the shell script may expose that token to local process listings while feishu_doc runs, and only add the cron job if you want recurring daily writes. Expect the skill to open/use browser automation, fetch public Solidot pages, write to Feishu when FEISHU_DOC_TOKEN is set, or save $WORKSPACE/solidot-push.md otherwise.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
fetch.sh:80
Finding

Feishu document token exposed through command-line arguments

Content
View full analysis
/dev/null || true echo "✅ 已推送到飞书文档" ``` ### Technical Analysis The script passes `FEISHU_DOC_TOKEN` directly to the `feishu_doc` executable using the `--doc_token` command-line argument. Command-line arguments may be exposed through process-inspection facilities such as `/proc//cmdline`, `ps`, process-monitoring tools, audit logs, or diagnostic telemetry. An attacker who can inspect processes under the applicable operating-system security policy may capture the token while `feishu_doc` is running. This violates least-privilege credential-handling principles because the secret is exposed to process metadata beyond the intended Feishu client. The document content is also supplied redundantly through both standard input and the `--content` argument. Although the generated content is limited to public Solidot article metadata, placing it in an argument unnecessarily exposes it through the same process-inspection channels. The command additionally suppresses errors with `2>/dev/null || true` and unconditionally prints a success message. This does not directly disclose the token, but it can conceal authentication failures or other delivery problems and impede detection. ### Attack Path 1. A user configures `FEISHU_DOC_TOKEN` and invokes `fetch.sh`. 2. The script launches `feishu_doc` with the token embedded in its command-line arguments. 3. During the lifetime of that process, a local attacker or monitoring component with sufficient process-inspection access reads the command line. 4. The attacker extracts the value supplied to `--doc_token`. 5. The attacker attempts to use the capture ...[truncated 896 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This finding identifies additional undeclared behaviors: browser automation, local file creation under WORKSPACE, and fallback local persistence when Feishu is not configured. Undeclared browser control and file writes expand the attack surface because users and platform policy may not expect these capabilities from a simple RSS-to-Feishu skill. The skill context makes this somewhat less severe than a credential-stealing tool, but the discrepancy is still a real security and trust problem.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding identifies additional undeclared behaviors: browser automation, local file creation under WORKSPACE, and fallback local persistence when Feishu is not configured. Undeclared browser control and file writes expand the attack surface because users and platform policy may not expect these capabilities from a simple RSS-to-Feishu skill. The skill context makes this somewhat less severe than a credential-stealing tool, but the discrepancy is still a real security and trust problem.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares commands that fetch remote content and read environment variables, but it does not define any explicit tool scope such as allowed-tools or permissions. That makes the skill’s runtime capabilities less transparent and increases the chance of unintended network access or secret exposure through environment usage. In this context the behavior appears aligned with the stated purpose, so the issue is more about missing restriction and disclosure than overtly malicious functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill mentions Feishu push and local file generation but does not clearly warn that it may write data to an external service or to local storage. Users need explicit notice before data leaves the current context or is persisted on disk, even if the content is just fetched news links. In this skill’s context, the data sensitivity is probably low, which limits impact, but the undisclosed write behavior is still a valid security concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are broad and could match ordinary discussion of Solidot rather than an intentional request to execute the skill. That can cause accidental invocation, leading to unexpected network requests or document/file writes. Because the skill performs outbound fetching and possible persistence, loose triggering has security relevance beyond simple usability.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest and module docstring say the skill fetches Solidot articles and pushes them to Feishu, implying an outbound delivery action. However, the implementation of push_to_feishu only checks an environment variable and prints the content or a readiness message, with no API call or actual push behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function docstring says '推送到飞书文档' and the inline comment says it uses the Feishu API to create or update a document. In reality, the function only prints content or a status message and returns, which directly contradicts the documented intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script accesses sensitive credentials from environment variables (FEISHU_APP_ID, FEISHU_APP_SECRET, FEISHU_DOC_TOKEN). While comments describe the script's purpose, there is no explicit user-facing notice that credentials will be read and used, which falls under missing warnings for sensitive environment variable access in code files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script conditionally writes generated content to a Feishu document, which is a networked external destination. Although it prints that content is being pushed, it does not clearly warn the user that data will be transmitted to Feishu or describe that external write behavior beyond a brief status message.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

文件中的描述、触发短语和定时任务名称均固定为中文,呈现出默认强制中文使用方式。若该技能面向通用用户环境,这种语言预设缺少明确的用户选择或适用范围说明,可能构成语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

All natural-language strings and comments in the script are Chinese, with no indication of language choice or scope limitation. Under the policy rule, forcing a specific language without opt-in can be a locale/language policy issue unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.