Back to skill

Security audit

feishu-calendar-meeting

Security checks for vulnerabilities and agentic risk

Overview

This Feishu calendar skill is purpose-aligned, but it tells agents to keep sensitive OAuth tokens in a plaintext workspace Markdown file without safeguards.

Review this before installing if your Feishu calendar contains sensitive business or personal information. Use a keychain or secret store for Feishu tokens instead of a Markdown file, restrict token scopes, avoid putting sensitive details in event titles/descriptions/locations, and revoke or rotate tokens if the workspace file may have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:31
Finding

Plaintext Storage of Feishu OAuth Tokens in the Workspace

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 31–37
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: Medium

Vulnerable Code Snippet

markdown
### 2. Token Management

- The access token is valid for approximately 2 hours.
- The refresh token is valid for approximately 30 days.
- Use the refresh token to renew access after expiration.

Tokens are stored in `~/.openclaw/workspace/feishu_tokens.md`.

The snippet above is an English rendering of the corresponding instructions in SKILL.md.

Technical Analysis

The Skill explicitly instructs the Agent to persist OAuth access and refresh tokens in a Markdown file under the OpenClaw workspace. It does not require encryption, owner-only file permissions, exclusion from indexing and backups, or use of an operating-system credential store.

OAuth bearer tokens must be treated as secrets because possession is generally sufficient for API authentication. The refresh token is particularly sensitive because it remains valid for approximately 30 days and can be used to obtain replacement access tokens after the short-lived access token expires.

Storing these credentials in a workspace Markdown file may expose them to other local users or processes, workspace indexing tools, backup systems, synchronization services, diagnostic collection, or accidental repository inclusion. Exploitation requires an attacker or unintended process to gain read access to that file; the Skill does not itself transmit the token to an unrelated endpoint.

Attack Path

  1. A user completes the documented Feishu OAuth authorization process.
  2. The resulting access token and refresh token are stored in ~/.openclaw/workspace/feishu_tokens.md as instructed.
  3. Another local user, compromised process, workspace indexer, backup service, synchronization tool, or accidentally published artifact reads the plaintext file.
  4. The unauthorized party extr ...[truncated 941 chars]
Remediation
View remediation

Remediation Suggestions

  1. Store OAuth access and refresh tokens in an operating-system keychain, managed secret store, or dedicated credential service rather than a Markdown workspace file.
  2. If file-backed storage is unavoidable, place the credential file outside the workspace and enforce owner-only permissions such as mode 0600 on Unix-like systems.
  3. Encrypt credentials at rest with keys maintained separately from the token file.
  4. Exclude credential files from source control, workspace indexing, synchronization, backup exports, diagnostics, and log collection.
  5. Never print tokens in command output or include them in generated reports. Redact authorization headers and token values from logs and errors.
  6. Request only the minimum Feishu OAuth scopes required for the active operation.
  7. Implement secure token rotation and immediate revocation after suspected exposure. Delete obsolete access and refresh tokens when authorization is removed.
  8. Document the expected token-file ownership and permission checks, and refuse to use storage that is readable by other users.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to store and reuse a Feishu user access token from a local markdown file but does not warn that this token is a sensitive bearer credential. Anyone or any process that can read that file can impersonate the user against Feishu APIs until expiry, and the guidance normalizes insecure credential handling in a general workspace path.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
# 可选:用户指定地点时添加
# "location": "地点"

curl -s -X POST "https://open.feishu.cn/open-apis/calendar/v4/calendars/${CALENDAR_ID}/events" \
  -H "Authorization: Bearer $USER_TOKEN" \
  -H "Content-Type: application/json" \
  -d "$JSON"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documented curl flow sends calendar content and a bearer token to Feishu's external API but does not clearly disclose that meeting metadata will leave the local environment and be transmitted to a third party. This can lead users to share sensitive titles, descriptions, locations, or schedules without informed consent, especially in enterprise settings.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.