Back to skill

Security audit

实施项目经理

Security checks for vulnerabilities and agentic risk

Overview

The skill matches a Feishu project-management purpose, but it ships a Feishu app secret and automatically makes new project sheets editable across the organization.

Review before installing. Rotate and remove the exposed Feishu App Secret, require credentials through a protected secret mechanism, disable token printing and insecure source-tree caching, make new sheets private by default, require explicit approval before broadening sharing, and reduce Feishu scopes to only the operations actually needed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/feishu_api.py:12
Finding

Hard-Coded Feishu Application Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/feishu_api.py:16
Finding

Tenant Bearer Token Stored and Printed Insecurely

Content
View full analysis
time.time() + 300: return cache["token"] # Request omitted token = result["tenant_access_token"] expire_time = time.time() + result.get("expire", 7200) # Write cache with open(TOKEN_CACHE, "w") as f: json.dump({"token": token, "expire_time": expire_time}, f) return token ``` ```python if __name__ == "__main__": action = sys.argv[1] if len(sys.argv) > 1 else "token" if action == "token": print(get_token()) elif action == "test": # Test API connectivity token = get_token() print(f"Token obtained successfully: {token[:20]}...") ``` ### Technical Analysis The tenant access token is written into the project script directory without explicitly enforcing restrictive file permissions. The resulting permissions depend on the process umask and surrounding filesystem configuration. On a shared host, permissive umask, shared workspace, backup process, or artifact collector could expose the cache to unauthorized parties. The command-line interface also prints the entire token when invoked with the default `token` action. The `test` action prints the first 20 characters. Token output can be captured by terminal recording, CI logs, orchestration logs, Agent transcripts, debugging tools, or redirected outp ...[truncated 1610 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/feishu_api.py:64
Finding

Arbitrary Destination Receives Tenant Authorization Header

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/feishu_sheet.py:82
Finding

Excessive Tenant Permissions and Automatic Organization-Wide Edit Access

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (24)

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/feishu_api.py (reported line 43)May include surrounding context.

python
)

    try:
        with urllib.request.urlopen(req, timeout=10) as resp:
            result = json.loads(resp.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        print(f"❌ 获取 token 失败: HTTP {e.code}", file=sys.stderr)

Tainted flow: 'req' from os.environ.get (line 73, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/feishu_api.py (reported line 76)May include surrounding context.

python
req = urllib.request.Request(url, data=data, headers=headers, method=method)

    try:
        with urllib.request.urlopen(req, timeout=15) as resp:
            return json.loads(resp.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        error_body = e.read().decode("utf-8")

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow states that new sheets are automatically set to organization-editable but does not prominently warn the user that this broadens access and editability across the tenant. Because the data includes contract, payment, budget, and risk information, omission of a clear warning undermines informed consent and increases the likelihood of unintended exposure and tampering.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document contains a plaintext Feishu App Secret, which is a sensitive credential that can allow unauthorized parties to obtain tenant access tokens and interact with the application's data and APIs. In this skill, the secret is directly tied to project-management spreadsheets and documents, so exposure could lead to unauthorized reading or modification of business records.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Publishing an application secret in markdown without any handling guidance exposes a live credential to anyone who can read the repository or skill files. Because the configuration explicitly uses tenant_access_token for a self-built enterprise app, the leaked secret can be used to impersonate the application and access or alter Feishu resources.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code changes Feishu permissions to tenant-wide editable via set_edit_permission(), which is a sensitive privilege-management operation unrelated to simple project data read/update. Because this skill handles operational and financial project records, making a sheet organization-wide editable can expose sensitive data and allow unauthorized modification, fraud, or accidental corruption at scale.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill describes capabilities that read secrets, access files, write files, and call external APIs, but it does not declare any explicit tool scope or permission boundaries. This increases the chance of over-privileged execution, unintended data access, and unsafe tool invocation beyond the narrow PM workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad everyday business terms like '项目管理', '进度报告', and '合同跟踪', which can cause accidental invocation in ordinary conversation. Because this skill can read and update Feishu sheets, unintended activation may result in unauthorized data access or modifications being initiated under ambiguous user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

L073 明确写明“生成中文 markdown 文档”,但文档未说明这是可配置选项,也未给出用户语言偏好选择机制。对于通用项目管理技能,默认强制单一语言输出可能违反语言/locale 选择政策。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The 'new project' and daily operation flows allow actions like locating sheets, reading data, creating project tables, and updating records without defining clear scope constraints such as which projects the user may access or modify. In a multi-project environment, this ambiguity raises the risk of cross-project access, accidental updates, or unauthorized creation of shared assets.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Automatically setting every new project sheet to organization-wide editable exposes project schedules, budgets, contract/payment status, and risk data to unnecessary modification by any internal user. In a project-management context, this can lead to unauthorized edits, data tampering, privacy leakage, and loss of integrity in the system of record.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The configuration instructs the system to make all newly created spreadsheets organization-editable by default, which weakens integrity controls and broadens who can modify project data. In a project-management skill that tracks milestones, contracts, payments, and status data, this increases the risk of unauthorized edits, accidental corruption, and fraud-related changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The requirements state that all document output must be in Chinese markdown, which imposes a specific language policy. The file does not indicate that users can opt into another language or that the Chinese-only restriction is required for a documented region-specific compliance reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code file contains natural-language text indicating the skill is specifically a Chinese project-management calculation engine, and all user-facing CLI messages are also fixed in Chinese. Because the file provides no opt-in, language selection, or documented region-specific rationale, it may violate language/locale policy requirements for user choice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file contains hardcoded Feishu APP_ID and APP_SECRET defaults, embedding live credentials directly in source code. Anyone with code access can recover these secrets, obtain tenant access tokens, and interact with the associated Feishu tenant APIs, which is especially dangerous in a project-management skill that handles contracts, payments, and milestone data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script stores the tenant access token in a local cache file without setting restrictive file permissions or protecting the cache location. On shared systems or multi-user environments, another local user or process could read the token and use it to access Feishu resources until expiry.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill goes beyond the described workflow of reading, analyzing, confirming, and updating existing Feishu tables by creating entirely new spreadsheets and then broadening access permissions automatically. In a project-management context, these sheets may contain contracts, payment status, risk registers, and other sensitive business data, so silently creating new storage locations with wider access expands the attack surface and can lead to unintended data exposure or governance violations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code automatically creates a spreadsheet and immediately broadens it to organization-editable without any user confirmation or warning. In this skill’s context, where records include contracts, payments, and project risks, that behavior can cause sensitive business information to become editable by a much larger audience than intended, enabling unauthorized changes or accidental data leaks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation says the function creates five sheets including "项目总览" and automatically sets edit permissions. The actual code creates only four sheets listed in sheet_names and contains no permission-setting call, so the inline documentation materially contradicts implemented behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains all user-facing instructions and labels in Chinese, and there is no indication that users can opt into another language or that the template is intentionally limited to a Chinese-speaking audience. Under the policy rule for language or locale constraints, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire template is written in Chinese and presents the milestone format as the default without indicating that users may choose another language or that the template is intended only for a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire skill file is written in Chinese and does not indicate that the user can choose another language or that the locale restriction is required for a specific regional/compliance context. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Natural-language elements such as the module docstring, comments, and CLI messages are presented only in Chinese, with no indication that users can choose another language. This can violate language or locale policy when a skill forces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file's user-facing docstrings and CLI messages are written only in Chinese, which imposes a language choice on users. The file does not indicate that the tool is region-specific or provide any opt-in or alternative locale behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.