T09 · Insecure Skill Coding Practices
- Location
README.md:73- Finding
Plaintext Feishu Token Stored in Skill Configuration
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 73-77
Vulnerability Type: Plaintext credential storage
Risk Level: MediumThe documentation explicitly instructs users to store a Feishu document token directly in
SKILL.md:markdown ## Configure Feishu (Optional) Configure the Feishu document token in SKILL.md: ```yaml feishu_doc_token: "your-doc-token"text ### Technical Analysis `SKILL.md` is ordinary project content rather than a protected secret store. Placing a real Feishu token in this file can expose it to source-control history, skill packages, backups, diagnostic output, agent context, logs, or other users and processes that can read the project directory. The token shown is a placeholder, and no live credential is present in the audited repository. The vulnerability arises because the documented configuration procedure encourages users to replace the placeholder with an actual credential in an insecure location. Exploitation does not require code execution. An attacker only needs access to a copy, log, prompt context, commit, backup, or distribution archive containing the modified `SKILL.md`. ### Attack Path 1. A user follows the README and writes a valid Feishu token into `SKILL.md`. 2. The skill directory is committed, packaged, backed up, logged, shared, or exposed to another local component. 3. An attacker obtains read access to the resulting file or artifact. 4. The attacker extracts the plaintext token. 5. The attacker presents the token to the relevant Feishu service or integration. 6. Feishu operations authorized by that token can be performed until the credential expires or is revoked. ### Impact Assessment The attacker can obtain the same Feishu access granted to the compromised token. Depending on the token's scope and resource permissions, this may expose or permit modification of synchronized child-language records and associated document metadata. T ...[truncated 229 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to place credentials directly in
SKILL.md. - Read the token at runtime from a protected environment variable or an approved secret-management service.
- Include only a non-sensitive variable reference in configuration, such as
FEISHU_DOC_TOKEN, rather than its value. - Ensure secret files are excluded from source control, skill packages, logs, backups, and agent-visible documentation.
- Apply restrictive filesystem permissions if a local secret file is unavoidable.
- Grant the token only the minimum document and API permissions required for synchronization.
- Prefer short-lived credentials where the Feishu integration supports them.
- Document credential rotation and immediate revocation procedures.
- Add automated secret scanning to source-control and packaging workflows.
- Rotate any real token that was previously stored in or distributed with
SKILL.md.
- Remove the instruction to place credentials directly in
