Back to skill

Security audit

Feishu Multi-Bot

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Feishu/OpenClaw setup skill, but it needs Review because its helper handles real AppSecrets unsafely and can generate unsafe config or shell commands from unvalidated input.

Review before installing or using in production. Do not pass real Feishu AppSecrets on the command line or paste generated output into shared logs, tickets, chats, or source control. Validate and sanitize agent IDs before using the helper, inspect generated JSON manually before merging it into openclaw.json, and treat pkill or gateway restart commands as potentially disruptive.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup-feishu-bots.sh:5
Finding

Feishu AppSecrets Are Exposed Through Process Arguments and Plaintext Output

Content
View full analysis
[agentId:appId:appSecret] ... # # Example: # ./setup-feishu-bots.sh orchestrator:cli_abc123:secret1 writer:cli_def456:secret2 coder:cli_ghi789:secret3 ``` ```bash for arg in "$@"; do IFS=':' read -r agent_id app_id app_secret <<< "$arg" if [ -z "$agent_id" ] || [ -z "$app_id" ] || [ -z "$app_secret" ]; then echo "Error: Invalid format '$arg'. Expected agentId:appId:appSecret" exit 1 fi AGENTS+=("$agent_id") APP_IDS+=("$app_id") APP_SECRETS+=("$app_secret") done FIRST_AGENT="${AGENTS[0]}" FIRST_APP_ID="${APP_IDS[0]}" FIRST_SECRET="${APP_SECRETS[0]}" ``` ```bash echo '{' echo ' "channels": {' echo ' "feishu": {' echo ' "enabled": true,' echo " \"appId\": \"$FIRST_APP_ID\"," echo " \"appSecret\": \"$FIRST_SECRET\"," echo ' "connectionMode": "websocket",' echo ' "accounts": {' for i in "${!AGENTS[@]}"; do account_id="${AGENTS[$i]}-bot" comma="" if [ $i -lt $((${#AGENTS[@]} - 1)) ]; then comma="," fi echo " \"$account_id\": {" echo " \"appId\": \"${APP_IDS[$i]}\"," echo " \"appSecret\": \"${APP_SECRETS[$i]}\"," echo " \"agent\": \"${AGENTS[$i]}\"" echo " }$comma" done ``` ### Technical Analysis The helper requires Feishu AppSecrets to be supplied directly as command-line arguments and then prints those secrets into terminal output as plaintext JSON. Command-line secrets can be exposed through: - Shell history files. - Process inspection facilities while the script is running. - Terminal session recording. - CI/CD command logs. - Debugging or monitoring software that captu ...[truncated 2055 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup-feishu-bots.sh:32
Finding

Unescaped User Input Enables Generated JSON Injection and Unsafe Workspace Commands

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to pass Feishu AppSecret values directly on the command line and to paste generated configuration into openclaw.json, but it provides no warning about protecting secrets or avoiding exposure through shell history, process listings, logs, or source control. In an infrastructure/setup skill, this omission is security-relevant because operators may copy production credentials into insecure places during normal use.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/build-guide.md (reported line 27)May include surrounding context.

md
| code-expert | 开发助手 | coder-bot | Dev group |
| analyst | 数据分析 | analyst-bot | Analytics group |

## Phase 2: Create Feishu Apps

For each agent that needs a bot:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

In this markdown file, openclaw doctor --fix is presented as a normal validation step, but the surrounding text does not disclose that the command can make changes automatically. For a safety-affecting operation in documentation, users should be warned when a command may alter config or system state rather than only inspect it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide explicitly labels this as a 'Full restart (kill existing + start fresh)' but does not provide a user warning about service interruption or impact on active sessions. Because this markdown instructs a potentially disruptive operation affecting system availability, a short caution is warranted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation recommends pkill to terminate the gateway process without warning that it can abruptly kill active OpenClaw sessions, disrupt service, and potentially affect multiple running OpenClaw processes. In a troubleshooting guide, users are likely to copy-paste commands directly, so omission of a safety note makes accidental denial-of-service more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The force-kill-and-restart sequence encourages abrupt termination as a remediation step but does not explain the risk of service interruption, loss of in-flight work, or unintended termination of unrelated OpenClaw components matching the process pattern. Because it is framed as a fix, operators may use it in production without understanding operational consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Listing a one-line pkill -f openclaw && ... command in a 'Useful Commands' section normalizes destructive process termination and makes unsafe copy-paste execution likely. In the context of an operations guide for multi-bot messaging infrastructure, this can cause avoidable downtime or kill more processes than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script emits Feishu AppSecrets directly to stdout as part of generated JSON, which can expose credentials through terminal scrollback, shell history workflows, CI logs, screen recording, or copy/paste into shared channels. In this skill context, the script is explicitly for configuring multiple production bot identities, so the exposed secrets are real integration credentials that could allow unauthorized bot access or impersonation if captured.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup-feishu-bots.sh (reported line 162)May include surrounding context.

sh
# --- Workspace creation commands ---
echo "=== Workspace Setup Commands ==="
echo "(Run these to create agent workspaces)"
echo ""

for agent in "${AGENTS[@]}"; do

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file includes an operational command to run openclaw gateway restart, which affects system availability, but the README does not warn that it will restart the gateway or may interrupt service. For markdown files, safety-relevant behaviors that affect system integrity should be disclosed to the user.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The diagram labels bot identities in Chinese (e.g. 总调度bot, 写作bot, 开发bot, 分析bot) without any explanation that the skill is region-specific or that language is configurable. This can violate language/locale policy because it implicitly fixes part of the user-facing experience to a specific language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.