Back to skill

Security audit

DingTalk API

Security checks for vulnerabilities and agentic risk

Overview

This DingTalk API skill includes powerful approval workflow actions that are only partially disclosed at the top level and are not clearly scoped or confirmation-gated.

Install only if you intentionally want to grant a DingTalk internal app access to organization data, bot messaging, and OA approval workflow actions. Use a least-privileged DingTalk app, avoid production credentials until tested, and require human review before running approval create, terminate, agree/refuse, transfer, comment, git push, or publish commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (134)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document instructs the agent to automatically execute git push and ClawHub publication, but provides no warning, consent checkpoint, or preview of what will be sent externally. Because these actions modify remote state and may expose code or trigger production distribution, lack of confirmation materially increases the chance of accidental release, data leakage, or unauthorized deployment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Several approval-related queries and mutating operations are present in the documentation even though the top-level skill description excludes them. In a corporate DingTalk context, hidden workflow capabilities are especially dangerous because they can expose sensitive approval data and alter business processes such as leave, reimbursement, or internal authorization flows.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: lodash==4.17.23 — 2 advisory(ies): CVE-2025-13465 (lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and ); CVE-2021-23337 (lodash vulnerable to Code Injection via `_.template` imports key names)

High
Category
Supply Chain
Confidence
96% confidence
Finding

This lockfile pins lodash 4.17.23, which is flagged for known vulnerabilities including prototype pollution and code-injection risk in specific APIs such as _.unset and _.template. Even though lodash is only a transitive dependency here (via @darabonba/typescript) and package-lock.json itself is not executable code, shipping a known-vulnerable version increases supply-chain risk if the vulnerable functions are reachable anywhere in the skill’s runtime or build pipeline.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The package metadata and skill manifest context describe only user/department lookup and messaging, but the scripts expose powerful OA approval operations such as create, terminate, execute, transfer, and comment on approval tasks. This capability gap is security-relevant because downstream users, reviewers, or policy engines may grant or invoke the skill under the false assumption that it is read-oriented or limited to messaging, enabling unauthorized workflow manipulation in DingTalk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This script introduces a capability to add comments to approval workflow instances, which is a write/action operation not disclosed in the skill metadata. Hidden or undocumented workflow-modification functionality is dangerous because an agent or operator may invoke it under the assumption the skill only performs user/department lookup and messaging, enabling unauthorized business-process interaction and audit noise or social engineering within approval records.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function at this location performs a direct modification of an approval instance by posting a comment using application credentials, despite the skill's stated purpose not justifying approval workflow changes. In an agent setting, this mismatch increases the risk of confused-deputy abuse: a user may obtain unintended influence over enterprise approval records, potentially inserting misleading comments or impersonation-like workflow annotations via arbitrary userId input.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This script adds a privileged capability to create DingTalk approval workflow instances, but that capability is not disclosed in the skill manifest, which only describes lookup, messaging, bot listing, and resigned-employee queries. Hidden or undocumented write actions are dangerous because an agent or user may invoke them without realizing the skill can trigger business workflows, causing unauthorized approvals, record creation, or process abuse in a production tenant.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code path in createApprovalInstance performs a state-changing workflow action that is unjustified by the skill's stated purpose, making it an unexpected privilege escalation within the skill package. In the context of an agent skill, undocumented action capability is especially risky because it can be composed into higher-level automations that create approval instances on behalf of users or departments without informed consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script performs DingTalk approval-task execution (agree/refuse) even though the manifest description only mentions user/department queries, messaging, bot listing, and resigned-employee queries. This capability enables real workflow decisions with enterprise impact while being hidden from the declared skill scope, which undermines review, consent, and least-privilege expectations. In this skill context, the mismatch is especially dangerous because approval actions are sensitive administrative operations rather than read-only queries.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.