T09 · Insecure Skill Coding Practices
- Location
src/index.ts:489- Finding
Path Traversal Through Unvalidated Agent Identifiers
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real Feishu multi-agent setup helper, but it stores secrets and writes persistent agent files with insufficient validation.
Review this before installing. Only use it in a trusted local OpenClaw environment, avoid custom agent IDs or names containing path characters, newlines, or instructions, treat Feishu App Secrets as sensitive, inspect generated openclaw.json and SOUL.md files before restart, and pin any npx-installed dependencies yourself.
src/index.ts:489Path Traversal Through Unvalidated Agent Identifiers
src/index.ts:538Persistent Agent Instruction Injection Through Custom Agent Names
src/index.ts:266Secret-Bearing Configuration Backups Are Created Without Explicit Restrictive Permissions
src/index.ts:638Unpinned Third-Party Package Execution Recommended Through npx
handlebars 4.7.8 has multiple serious advisories including prototype pollution and possible code or script injection through template compilation and partial handling. Even as a dev dependency, this is the most concerning finding because template engines are frequently fed semi-structured content in generators, test tooling, or scaffolding, and successful exploitation can lead to code execution or XSS-like impacts depending on usage.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
��会提供详细的创建教程 4. 配置凭证 - 逐个输入每个 Bot 的 App ID 和 App Secret 5. 验证并生成 - 自动验证凭证并生成配置 6. 重启生效 - 重启 OpenClaw 使配置生效
| 角色 | 职责 | 表情 |
|---|---|---|
| main | 大总管 - 统筹全局、分配任务 | 🎯 |
| dev | 开发助理 - 代码开发、技术架构 | 🧑💻 |
| content | 内容助理 - 内容创作、文案撰写 | ✍️ |
| ops | 运营助理 - 用户增长、活动策划 | 📈 |
| law | 法务助理 - 合同审核、合规咨询 | 📜 |
| finance | 财务助理 - 账目统计、预算管理 | 💰 |
请告诉我:你想创建几个 Agent?
例如:
回复数字或"自定义",我们开始吧!😊
---
### 步骤 2:选择 Agent 数量
*
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
声明描述的是一个具备多项管理与自动化能力的技能,但给出的代码片段只是 src/types.d.ts 类型定义,用于描述运行时上下文接口。该代码没有展示任何与多 Agent 配置、批量操作、凭证校验、模板管理或备份相关的行为,也没有可执行逻辑。由于代码的实际作用与声明的主要目的存在实质性差异,因此应判定为不匹配。
声明描述的是一个功能较完整的“交互式多 Agent 管理/配置”技能,包含批量创建、凭证验证、角色模板、自动备份等能力。但给出的代码片段只是测试代码,不是功能实现代码;其实际行为仅包括:导入 main 并断言其存在,以及对飞书凭证格式做简单字符串规则测试(AppID 以 cli_ 开头、AppSecret 长度为 32)。因此,该代码片段与声明用途存在明显不一致,尤其在主要目的和能力范围上差异很大。
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
---
id: feishu-multi-agent-manager
owner_id: rfdiosuao
name: 飞书多 Agent 配置助手
description: 交互式引导配置多 Agent 系统,支持批量创建、凭证验证、角色模板、自动备份
version: 2.0.4
icon: "\U0001F916"
author: rfdiosuao
metadata:
clawdbot:
emoji: "\U0001F916"
requires:
bins: []
---
# 飞书多 Agent 配置助手 🤖
> 交互式引导配置多 Agent 系统,支持批量创建、凭证验证、角色模板
## ✨ 功能特性
### 1. 交互式配置向导
- 像聊天一样完成配置
- 询问创建几个 Agent(1-10)
- 提供预设角色推荐
### 2. 批量创建支持
- 一次性创建多个 Agent
- 自动验证每个�
brace-expansion 1.1.12 is flagged for multiple denial-of-service issues involving pathological brace patterns that can trigger excessive CPU or memory consumption. Even though it is transitive and primarily in tooling paths, a vulnerable parser in CI, linting, test discovery, or developer automation can still be crashed by crafted input.
js-yaml 3.14.2 has reported CPU-exhaustion issues when parsing crafted YAML structures, including merge-key abuse and quadratic behavior. In this project it appears in dev tooling, which lowers exposure, but any workflow that parses untrusted YAML in automation or local setup could be vulnerable to denial of service.
brace-expansion 2.0.2 is separately present and affected by DoS conditions similar to the 1.x branch, allowing crafted expansion input to consume excessive resources or hang processes. Multiple vulnerable copies increase attack surface across tooling that performs glob or pattern expansion.
browserslist 4.28.1 is flagged for crash/prototype-write and unbounded memory growth issues when handling untrusted stats or distinct query results. In this repository it is likely used by build/test tooling, so the main danger is denial of service or unsafe object mutation in tooling pipelines rather than direct production compromise.
flatted 3.4.1 is reported vulnerable to prototype pollution during parse(), which can let crafted input modify object prototypes and potentially alter application or tooling behavior. Although this appears in development dependencies, prototype pollution can have broad downstream effects if untrusted serialized input is processed.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
};
compaction?: {
mode: string;
};
};
list: AgentConfig[];
};
channels: {
feishu: {
enabled: boolean;
accounts: Record<string, FeishuAccount>;
};
};
bindings: Array<{
agentId: string;
match: {
channel: string;
accountId: string;
peer?: {
kind: 'direct' | 'group';
id: string;
};
};
}>;
tools: {
agentToAgent: {
enabled: boolean;
allow: string[];
};
};
}
interface AgentTemplate {
id: string;
name: string;
role: string;
soulTemplate: string;
}
// ============================================================================
// 预定义的 Agent 角色模板
// ============================================================================
const AGENT_TEMPLATES: Record<string, AgentTemplate> = {
main: {
id: 'main',
name: '大总管',
role: '首席助理,专注于统筹全局、任务分配和跨 Agent 协调',
soulTemplate: `# SOU
The skill explicitly instructs users to paste App ID and App Secret into the bot conversation for validation. In a chat-based agent environment, messages may be logged, retained, visible to operators, or exposed to other tools/plugins, so prompting users to submit secrets through chat creates a direct credential disclosure risk.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
grep -i "error|fail" /home/node/.openclaw/run.log | tail -20
curl -X POST "https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal"
-H "Content-Type: application/json"
-d '{"app_id":"cli_xxx","app_secret":"xxx"}'
The README makes conflicting security claims: it says each agent has isolated authentication, but the changelog earlier states that new agents automatically copy auth-profiles.json from an existing agent. That inconsistency can cause credential reuse or cross-agent trust leakage, undermining the documented isolation model and potentially exposing one agent's auth context to another.
Without declared permissions the skill's intent is opaque and cannot be validated.
The skill explicitly discusses credential handling and automatic backup/modification of configuration, but it does not present clear warnings about secret sensitivity, storage, disclosure risks, or filesystem changes. Users may provide AppSecret values or approve config edits without informed consent, increasing the chance of credential leakage or unintended persistent changes.
The trigger phrase '开始配置' is overly broad and not scoped to Feishu or multi-agent setup, so the skill could activate in unrelated conversations. In a skill that claims to handle credentials and configuration changes, accidental activation raises the risk of prompting for secrets or initiating config-altering flows without clear user intent.
This skill persists Feishu App ID/App Secret values into openclaw.json and also creates a backup file containing prior configuration state. For a skill presented as a configuration assistant, storing secrets on disk materially increases credential exposure risk through local compromise, backups, logs, or later accidental disclosure.
The skill writes sensitive credentials and related configuration to disk during creation without an immediate user-facing warning on that execution path. In context, this is more dangerous because users are guided interactively to paste secrets into a trusted assistant, making silent persistence easy to overlook.
The skill expands the global agentToAgent.allow list for every created agent, broadening inter-agent communication privileges beyond simple Feishu bot setup. This increases lateral movement and abuse potential if any agent becomes compromised or behaves unexpectedly.
The skill instructs users to install and run an external package via npx -y @larksuite/openclaw-lark without pinning a specific version. That creates a supply-chain risk because a future compromised or breaking release would be fetched automatically in a high-trust setup path for agent configuration.
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
}
}
exports.default = main;
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoiaW5kZXguanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIuLi9zcmMvaW5kZXgudHMiXSwibmFtZXMiOltdLCJtYXBwaW5ncyI6IjtBQUFBOzs7Ozs7Ozs7OztHQVdHOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OztBQWdqQkgsb0JBa1VDO0FBLzJCRCx1Q0FBeUI7QUFDekIsMkNBQTZCO0FBa0U3QiwrRUFBK0U7QUFDL0Usa0JBQWtCO0FBQ2xCLCtFQUErRTtBQUUvRSxNQUFNLGVBQWUsR0FBa0M7SUFDckQsSUFBSSxFQUFFO1FBQ0osRUFBRSxFQUFFLE1BQU07UUFDVixJQUFJLEVBQUUsS0FBSztRQUNYLElBQUksRUFBRSw4QkFBOEI7UUFDcEMsWUFBWSxFQUFFOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7O0NBc0JqQjtLQUNFO0lBQ0QsR0FBRyxFQUFFO1FBQ0gsRUFBRSxFQUFFLEtBQUs7UUFDVCxJQUFJLEVBQUUsTUFBTTtRQUNaLElBQUksRUFBRSwwQkFBMEI7UUFDaEMsWUFBWSxFQUFFOzs7Ozs7Ozs7Ozs7Ozs7Ozs7OztDQW9CakI7S0FDRTtJQUNELE9BQU8sRUFBRTtRQUNQLEVBQUUsRUFBRSxTQUFTO1FBQ2IsSUFBSSxFQUFFLE1BQU07UUFDWixJQUFJLEVBQUUsMEJBQTBCO1FBQ2hDLFlBQVksRUFBRTs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Q0FvQmpCO0tBQ0U7SUFDRCxHQUFHLEVBQUU7UUFDSCxFQUFFLEVBQUUsS0FBSztRQUNULElBQUksRUFBRSxNQUFNO1FBQ1osSUFBSSxFQUFFLDBCQUEwQjtRQUNoQyxZQUFZLEVBQUU7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OztDQXFCakI7S0FDRTtJQUNELEdBQUcsRUFBRTtRQUNILEVBQUUsRUFBRSxLQUFLO1FBQ1QsSUFBSSxFQUFFLE1BQU07UUFDWixJQUFJLEVBQUUsd0JBQXdCO1FBQzlCLFlBQVksRUFBRTs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Q0FvQmpCO0tBQ0U7SUFDRCxPQUFPLEVBQUU7UUFDUCxFQUFFLEVBQUUsU0FBUztRQUNiLElBQUksRUFBRSxNQUFNO1FBQ1osSUFBSSxFQUFFLHdCQUF3QjtRQUM5QixZQUFZLEVBQUU7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7O0NBb0JqQjtLQUNFO0NBQ0YsQ0FBQztBQUVGLCtFQUErRTtBQUMvRSxPQUFPO0FBQ1AsK0VBQStFO0FBRS9FOztHQUVHO0FBQ0gsU0FBUyxrQkFBa0IsQ0FBQyxVQUFrQjtJQUM1QyxNQUFNLE9BQU8sR0FBRyxFQUFFLENBQUMsWUFBWSxDQUFDLFVBQVUsRUFBRSxPQUFPLENBQUMsQ0FBQztJQUNyRCxPQUFPLElBQUksQ0FBQyxLQUFLLENBQUMsT0FBTyxDQUFDLENBQUM7QUFDN0IsQ0FBQztBQUVEOztHQUVHO0FBQ0g7O0dBRUc7QUFDSCxTQUFTLFlBQVksQ0FBQyxVQUFrQjtJQUN0QyxNQUFNLFVBQVUsR0FBRyxHQUFHLFVBQVUsV0FBVyxJQUFJLENBQUMsR0FBRyxFQUFFLEVBQUUsQ0FBQztJQUN4RCxNQUFNLE9BQU8sR0FBRyxFQUFFLENBQUMsWUFBWSxDQUFDLFVBQVUsRUFBRSxPQUFPLENBQUMsQ0FBQztJQUNyRCxFQUFFLENBQUMsYUFBYSxDQUFDLFVBQVUsRUFBRSxPQUFPLEVBQUUsT0
...[truncated 27 chars]
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
}
}
exports.default = main;
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoiaW5kZXguanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIuLi9zcmMvaW5kZXgudHMiXSwibmFtZXMiOltdLCJtYXBwaW5ncyI6IjtBQUFBOzs7Ozs7Ozs7OztHQVdHOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OztBQWdqQkgsb0JBa1VDO0FBLzJCRCx1Q0FBeUI7QUFDekIsMkNBQTZCO0FBa0U3QiwrRUFBK0U7QUFDL0Usa0JBQWtCO0FBQ2xCLCtFQUErRTtBQUUvRSxNQUFNLGVBQWUsR0FBa0M7SUFDckQsSUFBSSxFQUFFO1FBQ0osRUFBRSxFQUFFLE1BQU07UUFDVixJQUFJLEVBQUUsS0FBSztRQUNYLElBQUksRUFBRSw4QkFBOEI7UUFDcEMsWUFBWSxFQUFFOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7O0NBc0JqQjtLQUNFO0lBQ0QsR0FBRyxFQUFFO1FBQ0gsRUFBRSxFQUFFLEtBQUs7UUFDVCxJQUFJLEVBQUUsTUFBTTtRQUNaLElBQUksRUFBRSwwQkFBMEI7UUFDaEMsWUFBWSxFQUFFOzs7Ozs7Ozs7Ozs7Ozs7Ozs7OztDQW9CakI7S0FDRTtJQUNELE9BQU8sRUFBRTtRQUNQLEVBQUUsRUFBRSxTQUFTO1FBQ2IsSUFBSSxFQUFFLE1BQU07UUFDWixJQUFJLEVBQUUsMEJBQTBCO1FBQ2hDLFlBQVksRUFBRTs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Q0FvQmpCO0tBQ0U7SUFDRCxHQUFHLEVBQUU7UUFDSCxFQUFFLEVBQUUsS0FBSztRQUNULElBQUksRUFBRSxNQUFNO1FBQ1osSUFBSSxFQUFFLDBCQUEwQjtRQUNoQyxZQUFZLEVBQUU7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OztDQXFCakI7S0FDRTtJQUNELEdBQUcsRUFBRTtRQUNILEVBQUUsRUFBRSxLQUFLO1FBQ1QsSUFBSSxFQUFFLE1BQU07UUFDWixJQUFJLEVBQUUsd0JBQXdCO1FBQzlCLFlBQVksRUFBRTs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Q0FvQmpCO0tBQ0U7SUFDRCxPQUFPLEVBQUU7UUFDUCxFQUFFLEVBQUUsU0FBUztRQUNiLElBQUksRUFBRSxNQUFNO1FBQ1osSUFBSSxFQUFFLHdCQUF3QjtRQUM5QixZQUFZLEVBQUU7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7O0NBb0JqQjtLQUNFO0NBQ0YsQ0FBQztBQUVGLCtFQUErRTtBQUMvRSxPQUFPO0FBQ1AsK0VBQStFO0FBRS9FOztHQUVHO0FBQ0gsU0FBUyxrQkFBa0IsQ0FBQyxVQUFrQjtJQUM1QyxNQUFNLE9BQU8sR0FBRyxFQUFFLENBQUMsWUFBWSxDQUFDLFVBQVUsRUFBRSxPQUFPLENBQUMsQ0FBQztJQUNyRCxPQUFPLElBQUksQ0FBQyxLQUFLLENBQUMsT0FBTyxDQUFDLENBQUM7QUFDN0IsQ0FBQztBQUVEOztHQUVHO0FBQ0g7O0dBRUc7QUFDSCxTQUFTLFlBQVksQ0FBQyxVQUFrQjtJQUN0QyxNQUFNLFVBQVUsR0FBRyxHQUFHLFVBQVUsV0FBVyxJQUFJLENBQUMsR0FBRyxFQUFFLEVBQUUsQ0FBQztJQUN4RCxNQUFNLE9BQU8sR0FBRyxFQUFFLENBQUMsWUFBWSxDQUFDLFVBQVUsRUFBRSxPQUFPLENBQUMsQ0FBQztJQUNyRCxFQUFFLENBQUMsYUFBYSxDQUFDLFVBQVUsRUFBRSxPQUFPLEVBQUUsT0
...[truncated 27 chars]
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
}
}
exports.default = main;
//# sourceMappingURL=data:application/json;base64,eyJ2ZXJzaW9uIjozLCJmaWxlIjoiaW5kZXguanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIuLi9zcmMvaW5kZXgudHMiXSwibmFtZXMiOltdLCJtYXBwaW5ncyI6IjtBQUFBOzs7Ozs7Ozs7OztHQVdHOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OztBQWdqQkgsb0JBa1VDO0FBLzJCRCx1Q0FBeUI7QUFDekIsMkNBQTZCO0FBa0U3QiwrRUFBK0U7QUFDL0Usa0JBQWtCO0FBQ2xCLCtFQUErRTtBQUUvRSxNQUFNLGVBQWUsR0FBa0M7SUFDckQsSUFBSSxFQUFFO1FBQ0osRUFBRSxFQUFFLE1BQU07UUFDVixJQUFJLEVBQUUsS0FBSztRQUNYLElBQUksRUFBRSw4QkFBOEI7UUFDcEMsWUFBWSxFQUFFOzs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7O0NBc0JqQjtLQUNFO0lBQ0QsR0FBRyxFQUFFO1FBQ0gsRUFBRSxFQUFFLEtBQUs7UUFDVCxJQUFJLEVBQUUsTUFBTTtRQUNaLElBQUksRUFBRSwwQkFBMEI7UUFDaEMsWUFBWSxFQUFFOzs7Ozs7Ozs7Ozs7Ozs7Ozs7OztDQW9CakI7S0FDRTtJQUNELE9BQU8sRUFBRTtRQUNQLEVBQUUsRUFBRSxTQUFTO1FBQ2IsSUFBSSxFQUFFLE1BQU07UUFDWixJQUFJLEVBQUUsMEJBQTBCO1FBQ2hDLFlBQVksRUFBRTs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Q0FvQmpCO0tBQ0U7SUFDRCxHQUFHLEVBQUU7UUFDSCxFQUFFLEVBQUUsS0FBSztRQUNULElBQUksRUFBRSxNQUFNO1FBQ1osSUFBSSxFQUFFLDBCQUEwQjtRQUNoQyxZQUFZLEVBQUU7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7OztDQXFCakI7S0FDRTtJQUNELEdBQUcsRUFBRTtRQUNILEVBQUUsRUFBRSxLQUFLO1FBQ1QsSUFBSSxFQUFFLE1BQU07UUFDWixJQUFJLEVBQUUsd0JBQXdCO1FBQzlCLFlBQVksRUFBRTs7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7Q0FvQmpCO0tBQ0U7SUFDRCxPQUFPLEVBQUU7UUFDUCxFQUFFLEVBQUUsU0FBUztRQUNiLElBQUksRUFBRSxNQUFNO1FBQ1osSUFBSSxFQUFFLHdCQUF3QjtRQUM5QixZQUFZLEVBQUU7Ozs7Ozs7Ozs7Ozs7Ozs7Ozs7O0NBb0JqQjtLQUNFO0NBQ0YsQ0FBQztBQUVGLCtFQUErRTtBQUMvRSxPQUFPO0FBQ1AsK0VBQStFO0FBRS9FOztHQUVHO0FBQ0gsU0FBUyxrQkFBa0IsQ0FBQyxVQUFrQjtJQUM1QyxNQUFNLE9BQU8sR0FBRyxFQUFFLENBQUMsWUFBWSxDQUFDLFVBQVUsRUFBRSxPQUFPLENBQUMsQ0FBQztJQUNyRCxPQUFPLElBQUksQ0FBQyxLQUFLLENBQUMsT0FBTyxDQUFDLENBQUM7QUFDN0IsQ0FBQztBQUVEOztHQUVHO0FBQ0g7O0dBRUc7QUFDSCxTQUFTLFlBQVksQ0FBQyxVQUFrQjtJQUN0QyxNQUFNLFVBQVUsR0FBRyxHQUFHLFVBQVUsV0FBVyxJQUFJLENBQUMsR0FBRyxFQUFFLEVBQUUsQ0FBQztJQUN4RCxNQUFNLE9BQU8sR0FBRyxFQUFFLENBQUMsWUFBWSxDQUFDLFVBQVUsRUFBRSxPQUFPLENBQUMsQ0FBQztJQUNyRCxFQUFFLENBQUMsYUFBYSxDQUFDLFVBQVUsRUFBRSxPQUFPLEVBQUUsT0
...[truncated 27 chars]
No suspicious patterns detected.