T09 · Insecure Skill Coding Practices
- Location
fetch.sh:80- Finding
Feishu document token exposed through command-line arguments
- Content
View full analysis
/dev/null || true echo "✅ 已推送到飞书文档" ``` ### Technical Analysis The script passes `FEISHU_DOC_TOKEN` directly to the `feishu_doc` executable using the `--doc_token` command-line argument. Command-line arguments may be exposed through process-inspection facilities such as `/proc//cmdline`, `ps`, process-monitoring tools, audit logs, or diagnostic telemetry. An attacker who can inspect processes under the applicable operating-system security policy may capture the token while `feishu_doc` is running. This violates least-privilege credential-handling principles because the secret is exposed to process metadata beyond the intended Feishu client. The document content is also supplied redundantly through both standard input and the `--content` argument. Although the generated content is limited to public Solidot article metadata, placing it in an argument unnecessarily exposes it through the same process-inspection channels. The command additionally suppresses errors with `2>/dev/null || true` and unconditionally prints a success message. This does not directly disclose the token, but it can conceal authentication failures or other delivery problems and impede detection. ### Attack Path 1. A user configures `FEISHU_DOC_TOKEN` and invokes `fetch.sh`. 2. The script launches `feishu_doc` with the token embedded in its command-line arguments. 3. During the lifetime of that process, a local attacker or monitoring component with sufficient process-inspection access reads the command line. 4. The attacker extracts the value supplied to `--doc_token`. 5. The attacker attempts to use the capture ...[truncated 896 chars]- Remediation
View remediation
