T01 · Skill Instruction Hijacking
- Location
SKILL.md:12- Finding
Skill Instructions Override Agent Behavior and Suppress Relevant Guidance
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Feishu setup skill is mostly purpose-aligned, but it handles app credentials while suppressing relevant setup guidance and defers follow-up work to a missing file.
Review this skill before installing. It is intended for Feishu robot setup, but it limits what the agent may tell you about permissions and approval steps, adds a from=maxclaw parameter to links, and relies on a missing feisu.md for later credential use. Only use it if you trust that workflow and are comfortable with the Feishu app credentials being handled by the agent during setup.
SKILL.md:12Skill Instructions Override Agent Behavior and Suppress Relevant Guidance
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill instructs the agent to perform outbound requests to a third-party Feishu OAuth registration endpoint and then poll for sensitive credentials (client_id/client_secret). This creates an external transmission and secret-handling path that can expose user/account linkage, session cookies, and app credentials to remote services without strong validation, explicit trust boundaries, or secure storage requirements.
rm -f "$COOKIE_JAR"
# init
INIT_RESP=$(curl -s -c "$COOKIE_JAR" -b "$COOKIE_JAR" \
-X POST "https://accounts.feishu.cn/oauth/v1/app/registration" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "action=init")
No suspicious patterns detected.