Back to skill

Security audit

飞书知识管理

Security checks for vulnerabilities and agentic risk

Overview

This skill performs a coherent Feishu knowledge-management workflow, but it includes persistent scheduled document organization and broad write authority without clear scope or review safeguards.

Review carefully before installing. Use it only with a narrowly permissioned Feishu account or designated folder, confirm before storing sensitive or internal links, and avoid enabling the daily cron task unless you have clear scope, audit logs, rollback/version history, and a documented removal process.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Warning
Location
SKILL.md:38
Finding

Persistent Daily Agent Execution Through a Scheduled Task

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:38-43, 54-59
Vulnerability Type: Scheduled task persistence
Risk Level: Medium

Vulnerable Code

markdown
### 4. Periodic organization (scheduled task)

- Automatically organize the knowledge base every day at 09:00
- Check Feishu cloud storage for duplicate documents
- Optimize the knowledge-base structure
- Report the organization results
bash
openclaw cron add --name "Daily Knowledge Base Organization" --cron "0 9 * * *" --message "Please perform knowledge base organization" --channel feishu

Technical Analysis

The Skill instructs the user to register an OpenClaw cron task that sends an execution request to the Agent through the Feishu channel every day at 09:00. The scheduled task survives the Skill invocation and causes future Agent activity without requiring a new, explicit request for each run.

The recurring operation is broadly authorized to inspect duplicate documents, reorganize the knowledge-base structure, and update Feishu content. The instructions do not define strict document boundaries, a dry-run mode, confirmation requirements, least-privilege credentials, or safeguards against unintended destructive changes. Although creation of the task is presented as optional, executing the documented command establishes cross-session persistence.

Attack Path

  1. A user enables the documented periodic organization feature.
  2. The user or Agent executes the supplied openclaw cron add command.
  3. OpenClaw creates a persistent schedule that triggers every day at 09:00.
  4. The schedule sends an organization request to the Agent through Feishu.
  5. The Agent inspects Feishu cloud documents and may update, deduplicate, or restructure the knowledge base.
  6. These operations continue across sessions until the scheduled task is explicitly removed.

Impact Assessment

The scheduled task obtains recurring access equival ...[truncated 662 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove automatic cron registration from the default workflow and require explicit user authorization before creating any recurring task.
  • Prefer one-time, user-initiated cleanup runs where practical.
  • Display the exact schedule, channel, requested operations, accessible document scope, and removal command before obtaining consent.
  • Restrict the scheduled operation to an allowlist of designated folders or knowledge-base nodes.
  • Use a least-privilege Feishu identity that cannot access or modify unrelated documents.
  • Perform duplicate detection and structural analysis in read-only or dry-run mode first.
  • Require confirmation before deleting, merging, moving, or overwriting documents.
  • Preserve backups or document versions so unintended changes can be rolled back.
  • Record each scheduled execution and all resulting document changes in an audit log.
  • Add execution limits, idempotency controls, and failure alerts to prevent repeated damaging operations.
  • Provide and document a command for listing and removing the scheduled task.
  • Periodically require renewed user authorization instead of allowing the schedule to operate indefinitely.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises broad trigger phrases such as “整理知识”, “存入知识库”, and “归纳要点”, which can match ordinary conversation and cause the workflow to activate unexpectedly. Because activation leads to external content retrieval and storage into Feishu documents/knowledge bases, accidental triggering can result in unintended data ingestion, persistence, and downstream automated modifications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description states that external article links will be automatically fetched, stored as Feishu documents, and summarized into a knowledge base, but it does not clearly warn the user that external content will be transmitted, persisted, and organized automatically. This creates a meaningful consent and data-handling risk: users may provide links without realizing third-party content, sensitive material, or internal URLs could be copied into persistent collaboration systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The scheduled cleanup feature performs daily automated checks for duplicate documents, optimizes knowledge-base structure, and reports results, but there is no user-facing warning that stored content may be modified on an ongoing basis. In a knowledge-management context, silent recurring edits or reorganizations can cause data integrity issues, unexpected document changes, and loss of trust, especially if summaries or classifications are altered without review.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.