T09 · Insecure Skill Coding Practices
- Location
data/contact-cache.json:174- Finding
Production-Like Contact PII Included in the Distributed Package
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it claims, but it ships exposed contact data and can send real Feishu/Lark messages with weak recipient safeguards.
Review before installing. Remove the bundled contact-cache data, require preview and explicit confirmation for sends, reject ambiguous recipient matches, and scope or disable plaintext caching before using this with real Feishu/Lark accounts.
data/contact-cache.json:174Production-Like Contact PII Included in the Distributed Package
src/cache.js:4Contact Records Persisted in Plaintext Without Explicit Restrictive Permissions
src/cache.js:30Global Contact Cache Is Not Scoped by Feishu Account or Tenant
src/tool-feishu-message.js:491Message Actions Silently Select the First Ambiguous Directory Match
Without declared permissions the skill's intent is opaque and cannot be validated.
The code persistently stores personally identifiable contact data such as name, email, mobile number, and platform identifiers in a plaintext JSON file under a fixed path. In the context of a messaging skill that resolves and contacts real users, this creates unnecessary long-lived exposure of sensitive data to local attackers, other processes, backups, or logs if the host is shared or compromised.
The send_message action can transmit a live Feishu/Lark message immediately once called, gated only by pluginCfg.allowSend and without any in-code confirmation, approval, or enforced dry-run step. In an agent skill, this creates a real risky side effect: prompt injection, user ambiguity, or mistaken target resolution could cause unintended outbound messages to employees or chats.
The send_followup path builds a message and, unless dry_run is set, proceeds to send it live without requiring an explicit user-facing confirmation in code. Because this tool is specifically designed for work follow-ups and can resolve recipients from partial identifiers, an agent mistake or adversarial prompt could generate and send unintended nudges to the wrong person.
The send_contact_message action can send arbitrary content to a resolved contact or chat immediately when dry_run is not set, again without mandatory confirmation in the code path. This is dangerous in an agent context because the action supports free-form message content and target lookup, enabling accidental spam, disclosure, or social-engineering messages if the model is manipulated or misinterprets instructions.
The dependency uses a caret range, which permits automatic installation of newer minor/patch releases rather than a single immutable version. This weakens supply-chain reproducibility and can unexpectedly introduce vulnerable or malicious upstream code if the resolved package changes over time.
"description": "Feishu/Lark messaging plugin for OpenClaw with contact lookup, caching, direct messaging, and follow-up actions.",
"keywords": ["openclaw", "feishu", "lark", "message", "im", "chat"],
"dependencies": {
"@larksuiteoapi/node-sdk": "^1.59.0",
"@sinclair/typebox": "^0.34.48",
"openclaw": "^2026.3.22",
"zod": "^4.3.6"
The dependency is specified with a non-exact version range, so different installs may resolve to different package contents. This creates a supply-chain risk and reduces build determinism, making it harder to verify exactly what code is executed.
"keywords": ["openclaw", "feishu", "lark", "message", "im", "chat"],
"dependencies": {
"@larksuiteoapi/node-sdk": "^1.59.0",
"@sinclair/typebox": "^0.34.48",
"openclaw": "^2026.3.22",
"zod": "^4.3.6"
},
The openclaw dependency is not pinned to an exact version, allowing installs to drift across releases. In this case the risk is elevated because the package is the host framework for the skill and is reported to have multiple advisories, so version ambiguity makes it impossible to determine exposure and can pull in vulnerable code.
"dependencies": {
"@larksuiteoapi/node-sdk": "^1.59.0",
"@sinclair/typebox": "^0.34.48",
"openclaw": "^2026.3.22",
"zod": "^4.3.6"
},
"openclaw": {
The manifest does not pin openclaw to an exact version, and the package has multiple known advisories. Because the actual installed version cannot be verified from this manifest alone, consumers may unknowingly deploy a vulnerable release, which is more concerning here because the skill runs inside and depends on the OpenClaw runtime.
Using a caret range for zod allows the installed version to change without explicit review. Even if only patch/minor updates are expected, this still introduces uncertainty and can expose the skill to newly disclosed or compromised upstream releases.
"@larksuiteoapi/node-sdk": "^1.59.0",
"@sinclair/typebox": "^0.34.48",
"openclaw": "^2026.3.22",
"zod": "^4.3.6"
},
"openclaw": {
"extensions": ["./index.js"]
The zod version is not pinned exactly, and the package has a known advisory history. This makes it unclear whether deployments will resolve to a safe release, creating avoidable exposure and hindering reliable vulnerability assessment.
This code accesses configuration from process.env.OPENCLAW_CONFIG_PATH and ~/.openclaw/openclaw.json, which involves reading user/system data from potentially sensitive locations. There is no confirmation prompt, user-facing log, or explanatory comment/docstring disclosing that these files and environment-derived paths will be accessed.
No suspicious patterns detected.