T05 · Unauthorized Access and Privilege Escalation
- Location
README.md:64- Finding
Unnecessary Feishu Permissions Violate Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
README.md:64-68;SKILL.md:43-48
Vulnerability Type: Excessive and currently unused application permissions
Risk Level: MediumVulnerable Code Snippet
README.md:64-68:markdown ## 权限要求 使用前需要确保飞书应用有以下权限: - `im:message:read` - 读取消息 - `im:message:send` - 发送消息 - `im:chat:read` - 读取群组信息 - `im:user:read` - 读取用户信息SKILL.md:43-48:markdown ## Required Permissions - `im:message:read` - `im:message:send` - `im:chat:read`Technical Analysis
The documentation directs users to grant permissions for reading messages, sending messages, reading chat information, and, in the README, reading user information. However, the current implementation contains no Feishu API client, event subscription, authentication flow, or message-sending logic.
The
startcommand explicitly states atindex.js:108-112that message event subscription remains under development:javascript // 这里需要对接飞书消息事件订阅 // 实际实现需要配合 OpenClaw 的事件系统 console.log('⚠️ 消息事件订阅功能开发中,即将推出...'); console.log('目前版本仅支持规则测试功能');Therefore, none of the documented Feishu permissions are required by the code currently shipped. The
im:user:readpermission is also inconsistent because it appears inREADME.mdbut not inSKILL.md. Requesting permissions before the corresponding functionality exists violates the principle of least privilege.Attack Path
- An administrator follows the installation documentation.
- The administrator grants the listed Feishu scopes to an application or future integration.
- The current package does not use those scopes, but they remain assigned to the application.
- If the application credentials, a future package version, or a substituted integration is compromised, the attacker can exercise the unnecessarily granted scopes.
- Depending on Feishu's scope enforcement and tenant configuration, the attacker could read messa ...[truncated 708 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all Feishu permission requirements from the current documentation until Feishu connectivity is implemented.
- When integration is added, map every requested scope to a specific implemented operation and document that mapping.
- Request only the minimum scopes necessary for enabled features.
- Do not request
im:user:readorim:chat:readunless the implementation demonstrably needs user or chat data. - Keep
README.md,SKILL.md, application manifests, and deployment instructions synchronized. - Add an automated check that compares documented scopes with the scopes used by the implementation.
- Advise existing users to revoke any scopes already granted to the nonfunctional integration.
