Back to skill

Security audit

Feishu Report Summary

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for summarizing Feishu reports, but it handles sensitive workplace data with under-scoped safeguards for local exports and untrusted report content.

Install only if you trust the Feishu account context and are comfortable letting the skill retrieve detailed workplace report contents. Prefer stdout or a private, reviewed destination over /tmp or shared paths, avoid publishing summaries back to Feishu without checking the generated text, and treat all report field content as data rather than instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:11
Finding

Untrusted Feishu report content is processed without prompt-injection safeguards

Content
View full analysis
({ task_id: task.task_id || "", rule_id: task.rule_id || "", rule_name: task.rule_name || "", from_user_id: task.from_user_id || "", from_user_name: task.from_user_name || "", department_name: task.department_name || "", commit_time: task.commit_time || 0, commit_time_local: task.commit_time ? formatDateTime(task.commit_time) : "", to_user_ids: task.to_user_ids || [], to_user_names: task.to_user_names || [], fields: (task.form_contents || []).map((field) => ({ field_id: field.field_id || "", field_name: field.field_name || "", field_value_raw: field.field_value || "", field_value_pretty: prettyFieldValue(field.field_value || ""), })), })); } ``` ### Technical Analysis Feishu report fields are authored by users and therefore constitute untrusted input. The script preserves both the raw and rendered values without marking, escaping, or isolating them as untrusted data. At the same time, the Skill directs the Agent to load the resulting JSON into the model for analysis. This creates an indirect prompt-injection boundary: malicious instructions emb ...[truncated 1644 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_report_tasks.js:618
Finding

Sensitive report exports can be written to unrestricted paths with unsafe overwrite behavior

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/fetch_report_tasks.js:518
Finding

Generated exports unnecessarily disclose the local configuration path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The documented purpose frames the skill as a summarization helper, but the behavior includes additional capabilities such as arbitrary file output and reading local OpenClaw configuration and credentials. This mismatch is security-relevant because users and reviewers may grant trust based on a narrower description than what the skill actually does.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
1. Run `scripts/fetch_report_tasks.js` for the target day or range.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
1. Run `scripts/fetch_report_tasks.js` for the target day or range.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
1. Run `scripts/fetch_report_tasks.js` for the target day or range.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
1. Run `scripts/fetch_report_tasks.js` for the target day or range.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
1. Run `scripts/fetch_report_tasks.js` for the target day or range.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/fetch_report_tasks.js (reported line 391)May include surrounding context.

js
fail(`Multiple report rules matched "${ruleName}" exactly`);
  }
  if (rules.length === 1) {
    return rules[0];
  }
  if (rules.length === 0) {
    fail(`No report rule matched "${ruleName}"`);

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes code that can read environment/config-backed credentials, but the manifest declares no explicit tool scope or permissions boundary. That makes the skill's effective access broader and less auditable, increasing the chance of unintended secret use or data access when the skill is invoked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill does not warn users that it reads stored Feishu credentials and transmits report data to the Feishu Report API. Because the data involved is work-report content, this omission can lead to unintentional exposure of sensitive organizational information under the user's existing account context.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

The skill explicitly supports writing fetched report exports to arbitrary files for later review, which creates persistence of potentially sensitive report data on local disk. Even if intended for convenience, persisted digests or raw exports may outlive the session and be exposed through weak filesystem permissions, backups, or later unintended access.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

node scripts/fetch_report_tasks.js --days 7 --rule-name "研发团队工作日报" --format markdown

text

Write the export to a file for later review:

```bash
node scripts/fetch_report_tasks.js --date 2026-03-14 --output /tmp/feishu-report.md

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script builds a report payload and renders every fetched task, including reporter identity, recipients, department, timestamps, and full form field contents. That behavior exceeds the stated purpose of producing daily/weekly summaries and creates unnecessary exposure of potentially sensitive employee work-report data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script can write exported Feishu report data directly to an arbitrary user-supplied path, including sensitive work-report contents and user details, without any warning, permission check, redaction, or secure file mode handling. In the context of HR/team reporting data, this increases the risk of inadvertent local disclosure or persistence of confidential information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

To locate the SDK, the code runs external binaries such as npm and which via execFileSync. Spawning subprocesses to inspect the host environment is not an obvious requirement of a skill whose stated purpose is reading and summarizing Feishu reports, and the manifest does not mention this host-discovery capability.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/fetch_report_tasks.js:233