T09 · Insecure Skill Coding Practices
- Location
scripts/feishu_api.py:12- Finding
Hard-Coded Feishu Application Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches a Feishu project-management purpose, but it ships a Feishu app secret and automatically makes new project sheets editable across the organization.
Review before installing. Rotate and remove the exposed Feishu App Secret, require credentials through a protected secret mechanism, disable token printing and insecure source-tree caching, make new sheets private by default, require explicit approval before broadening sharing, and reduce Feishu scopes to only the operations actually needed.
scripts/feishu_api.py:12Hard-Coded Feishu Application Credentials
scripts/feishu_api.py:16Tenant Bearer Token Stored and Printed Insecurely
scripts/feishu_api.py:64Arbitrary Destination Receives Tenant Authorization Header
scripts/feishu_sheet.py:82Excessive Tenant Permissions and Automatic Organization-Wide Edit Access
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
)
try:
with urllib.request.urlopen(req, timeout=10) as resp:
result = json.loads(resp.read().decode("utf-8"))
except urllib.error.HTTPError as e:
print(f"❌ 获取 token 失败: HTTP {e.code}", file=sys.stderr)
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
req = urllib.request.Request(url, data=data, headers=headers, method=method)
try:
with urllib.request.urlopen(req, timeout=15) as resp:
return json.loads(resp.read().decode("utf-8"))
except urllib.error.HTTPError as e:
error_body = e.read().decode("utf-8")
The workflow states that new sheets are automatically set to organization-editable but does not prominently warn the user that this broadens access and editability across the tenant. Because the data includes contract, payment, budget, and risk information, omission of a clear warning undermines informed consent and increases the likelihood of unintended exposure and tampering.
The document contains a plaintext Feishu App Secret, which is a sensitive credential that can allow unauthorized parties to obtain tenant access tokens and interact with the application's data and APIs. In this skill, the secret is directly tied to project-management spreadsheets and documents, so exposure could lead to unauthorized reading or modification of business records.
Publishing an application secret in markdown without any handling guidance exposes a live credential to anyone who can read the repository or skill files. Because the configuration explicitly uses tenant_access_token for a self-built enterprise app, the leaked secret can be used to impersonate the application and access or alter Feishu resources.
The code changes Feishu permissions to tenant-wide editable via set_edit_permission(), which is a sensitive privilege-management operation unrelated to simple project data read/update. Because this skill handles operational and financial project records, making a sheet organization-wide editable can expose sensitive data and allow unauthorized modification, fraud, or accidental corruption at scale.
The skill describes capabilities that read secrets, access files, write files, and call external APIs, but it does not declare any explicit tool scope or permission boundaries. This increases the chance of over-privileged execution, unintended data access, and unsafe tool invocation beyond the narrow PM workflow.
The trigger phrases include broad everyday business terms like '项目管理', '进度报告', and '合同跟踪', which can cause accidental invocation in ordinary conversation. Because this skill can read and update Feishu sheets, unintended activation may result in unauthorized data access or modifications being initiated under ambiguous user intent.
L073 明确写明“生成中文 markdown 文档”,但文档未说明这是可配置选项,也未给出用户语言偏好选择机制。对于通用项目管理技能,默认强制单一语言输出可能违反语言/locale 选择政策。
The 'new project' and daily operation flows allow actions like locating sheets, reading data, creating project tables, and updating records without defining clear scope constraints such as which projects the user may access or modify. In a multi-project environment, this ambiguity raises the risk of cross-project access, accidental updates, or unauthorized creation of shared assets.
Automatically setting every new project sheet to organization-wide editable exposes project schedules, budgets, contract/payment status, and risk data to unnecessary modification by any internal user. In a project-management context, this can lead to unauthorized edits, data tampering, privacy leakage, and loss of integrity in the system of record.
The configuration instructs the system to make all newly created spreadsheets organization-editable by default, which weakens integrity controls and broadens who can modify project data. In a project-management skill that tracks milestones, contracts, payments, and status data, this increases the risk of unauthorized edits, accidental corruption, and fraud-related changes.
The requirements state that all document output must be in Chinese markdown, which imposes a specific language policy. The file does not indicate that users can opt into another language or that the Chinese-only restriction is required for a documented region-specific compliance reason.
This code file contains natural-language text indicating the skill is specifically a Chinese project-management calculation engine, and all user-facing CLI messages are also fixed in Chinese. Because the file provides no opt-in, language selection, or documented region-specific rationale, it may violate language/locale policy requirements for user choice.
The file contains hardcoded Feishu APP_ID and APP_SECRET defaults, embedding live credentials directly in source code. Anyone with code access can recover these secrets, obtain tenant access tokens, and interact with the associated Feishu tenant APIs, which is especially dangerous in a project-management skill that handles contracts, payments, and milestone data.
The script stores the tenant access token in a local cache file without setting restrictive file permissions or protecting the cache location. On shared systems or multi-user environments, another local user or process could read the token and use it to access Feishu resources until expiry.
The skill goes beyond the described workflow of reading, analyzing, confirming, and updating existing Feishu tables by creating entirely new spreadsheets and then broadening access permissions automatically. In a project-management context, these sheets may contain contracts, payment status, risk registers, and other sensitive business data, so silently creating new storage locations with wider access expands the attack surface and can lead to unintended data exposure or governance violations.
The code automatically creates a spreadsheet and immediately broadens it to organization-editable without any user confirmation or warning. In this skill’s context, where records include contracts, payments, and project risks, that behavior can cause sensitive business information to become editable by a much larger audience than intended, enabling unauthorized changes or accidental data leaks.
The documentation says the function creates five sheets including "项目总览" and automatically sets edit permissions. The actual code creates only four sheets listed in sheet_names and contains no permission-setting call, so the inline documentation materially contradicts implemented behavior.
This markdown file contains all user-facing instructions and labels in Chinese, and there is no indication that users can opt into another language or that the template is intentionally limited to a Chinese-speaking audience. Under the policy rule for language or locale constraints, forcing a specific language without user choice can be a natural-language policy violation.
The entire template is written in Chinese and presents the milestone format as the default without indicating that users may choose another language or that the template is intended only for a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
The entire skill file is written in Chinese and does not indicate that the user can choose another language or that the locale restriction is required for a specific regional/compliance context. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern.
Natural-language elements such as the module docstring, comments, and CLI messages are presented only in Chinese, with no indication that users can choose another language. This can violate language or locale policy when a skill forces a specific language without opt-in or justification.
The file's user-facing docstrings and CLI messages are written only in Chinese, which imposes a language choice on users. The file does not indicate that the tool is region-specific or provide any opt-in or alternative locale behavior.
No suspicious patterns detected.