T09 · Insecure Skill Coding Practices
- Location
scripts/setup-feishu-bots.sh:5- Finding
Feishu AppSecrets Are Exposed Through Process Arguments and Plaintext Output
- Content
View full analysis
[agentId:appId:appSecret] ... # # Example: # ./setup-feishu-bots.sh orchestrator:cli_abc123:secret1 writer:cli_def456:secret2 coder:cli_ghi789:secret3 ``` ```bash for arg in "$@"; do IFS=':' read -r agent_id app_id app_secret <<< "$arg" if [ -z "$agent_id" ] || [ -z "$app_id" ] || [ -z "$app_secret" ]; then echo "Error: Invalid format '$arg'. Expected agentId:appId:appSecret" exit 1 fi AGENTS+=("$agent_id") APP_IDS+=("$app_id") APP_SECRETS+=("$app_secret") done FIRST_AGENT="${AGENTS[0]}" FIRST_APP_ID="${APP_IDS[0]}" FIRST_SECRET="${APP_SECRETS[0]}" ``` ```bash echo '{' echo ' "channels": {' echo ' "feishu": {' echo ' "enabled": true,' echo " \"appId\": \"$FIRST_APP_ID\"," echo " \"appSecret\": \"$FIRST_SECRET\"," echo ' "connectionMode": "websocket",' echo ' "accounts": {' for i in "${!AGENTS[@]}"; do account_id="${AGENTS[$i]}-bot" comma="" if [ $i -lt $((${#AGENTS[@]} - 1)) ]; then comma="," fi echo " \"$account_id\": {" echo " \"appId\": \"${APP_IDS[$i]}\"," echo " \"appSecret\": \"${APP_SECRETS[$i]}\"," echo " \"agent\": \"${AGENTS[$i]}\"" echo " }$comma" done ``` ### Technical Analysis The helper requires Feishu AppSecrets to be supplied directly as command-line arguments and then prints those secrets into terminal output as plaintext JSON. Command-line secrets can be exposed through: - Shell history files. - Process inspection facilities while the script is running. - Terminal session recording. - CI/CD command logs. - Debugging or monitoring software that captu ...[truncated 2055 chars]- Remediation
View remediation
