Back to skill

Security audit

Baby Words Tracker

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent child-language tracking purpose, but it stores and syncs sensitive child records with insufficient privacy controls and recommends unsafe token storage.

Review before installing. Use this only if you are comfortable storing a child's speech history locally and syncing it to Feishu. Avoid putting a real Feishu token in SKILL.md; use a protected secret mechanism if available, limit the token's permissions, and confirm how records can be deleted or kept local-only.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:73
Finding

Plaintext Feishu Token Stored in Skill Configuration

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 73-77
Vulnerability Type: Plaintext credential storage
Risk Level: Medium

The documentation explicitly instructs users to store a Feishu document token directly in SKILL.md:

markdown
## Configure Feishu (Optional)

Configure the Feishu document token in SKILL.md:
```yaml
feishu_doc_token: "your-doc-token"
text

### Technical Analysis

`SKILL.md` is ordinary project content rather than a protected secret store. Placing a real Feishu token in this file can expose it to source-control history, skill packages, backups, diagnostic output, agent context, logs, or other users and processes that can read the project directory.

The token shown is a placeholder, and no live credential is present in the audited repository. The vulnerability arises because the documented configuration procedure encourages users to replace the placeholder with an actual credential in an insecure location.

Exploitation does not require code execution. An attacker only needs access to a copy, log, prompt context, commit, backup, or distribution archive containing the modified `SKILL.md`.

### Attack Path

1. A user follows the README and writes a valid Feishu token into `SKILL.md`.
2. The skill directory is committed, packaged, backed up, logged, shared, or exposed to another local component.
3. An attacker obtains read access to the resulting file or artifact.
4. The attacker extracts the plaintext token.
5. The attacker presents the token to the relevant Feishu service or integration.
6. Feishu operations authorized by that token can be performed until the credential expires or is revoked.

### Impact Assessment

The attacker can obtain the same Feishu access granted to the compromised token. Depending on the token's scope and resource permissions, this may expose or permit modification of synchronized child-language records and associated document metadata.

T
...[truncated 229 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the instruction to place credentials directly in SKILL.md.
  • Read the token at runtime from a protected environment variable or an approved secret-management service.
  • Include only a non-sensitive variable reference in configuration, such as FEISHU_DOC_TOKEN, rather than its value.
  • Ensure secret files are excluded from source control, skill packages, logs, backups, and agent-visible documentation.
  • Apply restrictive filesystem permissions if a local secret file is unavoidable.
  • Grant the token only the minimum document and API permissions required for synchronization.
  • Prefer short-lived credentials where the Feishu integration supports them.
  • Document credential rotation and immediate revocation procedures.
  • Add automated secret scanning to source-control and packaging workflows.
  • Rotate any real token that was previously stored in or distributed with SKILL.md.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README promotes automatic cloud synchronization and local database storage but does not give a clear privacy notice, retention policy, or warning that children’s speech data may be stored on disk and transmitted to a third-party platform. Because this skill handles potentially sensitive information about a minor, unclear data handling materially raises the risk of unintentional collection, disclosure, and compliance issues.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly describes automatic triggering on common conversational phrases like “记宝宝说/说了”, which can cause the skill to activate during ordinary family chat and record content unintentionally. In this skill’s context, accidental activation is more dangerous because the captured content concerns a child and is then persisted locally and potentially synced to Feishu, increasing privacy exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states it will automatically sync baby language records to Feishu cloud documents, but provides no notice, consent step, or data-sharing warning. Because the data concerns a child and may include developmental information, silent transmission to a third-party service creates a real privacy risk and can expose sensitive family data beyond the local environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill defines a persistent local JSON database for storing child-specific records, but does not warn the user that personal data will be retained on disk. Persistent storage of a child's language history, age, and related metadata without disclosure increases privacy risk, especially on shared devices or systems without access controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code embeds a fixed locale/language structure using Chinese defaults such as the child name "宝宝" and language buckets for 普通话, 广东话, and 英语. Because the skill does not provide any user opt-in or configurable locale selection, it appears to force a specific language/locale model rather than offering a choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.