Back to skill

Security audit

Meeting Minutes CN

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it advertises, but its Feishu sync command and handling of sensitive meeting content need review before use.

Install only if you intend meeting minutes to be synced to Feishu and action items stored locally. Avoid using it with confidential meetings unless you confirm the Feishu destination and replace the shell-style sync command with a safer argument-array or API-based invocation that treats meeting text as data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:36
Finding

Shell Command Injection Through Unsafely Interpolated Meeting Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 36-38
Vulnerability Type: Shell command injection
Risk Level: High

Vulnerable Code:

bash
python3 .claude/skills/feishu-doc/scripts/doc_ctl.py create "会议纪要 - {title} - {date}" --content "{minutes_content}"

Technical Analysis

The documented command directly interpolates the meeting title, date, and generated minutes into a shell command. These values can contain user-controlled meeting content.

Wrapping values in double quotes does not make shell interpolation safe. Shell constructs such as command substitutions remain active inside double quotes, while embedded quotation marks can terminate an argument and introduce additional shell syntax. For example, an attacker could place a command-substitution expression in a meeting title or include a quotation mark followed by a command separator in the meeting content.

If the agent constructs and executes this command through a shell, the malicious content is interpreted as shell syntax rather than being passed exclusively as data to doc_ctl.py.

Attack Path

  1. An attacker asks the skill to create meeting minutes and supplies a crafted title, date, or discussion content containing shell metacharacters or command substitution syntax.
  2. The skill fills the corresponding {title}, {date}, or {minutes_content} placeholder with that attacker-controlled value.
  3. The agent follows the Feishu synchronization instruction and executes the resulting command through a shell.
  4. The shell evaluates the injected syntax before or alongside the intended Python process.
  5. The attacker's command executes with the same operating-system identity and permissions as the agent process.

Exploitation depends on the agent executing the documented command through a shell and on attacker-controlled text reaching the placeholders without robust shell escaping.

Impact Assessment

Successful exploitati ...[truncated 713 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not construct a shell command by concatenating or interpolating meeting data.
  • Invoke the Python script with an argument-array API that bypasses shell parsing, such as Python subprocess.run([...], shell=False, check=True).
  • Prefer passing the potentially large minutes content through standard input or a dedicated API instead of a command-line argument.
  • If a temporary file is required, create it with restrictive permissions, use a trusted temporary-file API, and delete it after use.
  • Treat the title, date, and all generated meeting content as untrusted data. Apply validation and reasonable length limits before sending them to external services.
  • Do not rely solely on quote replacement or ad hoc escaping. If shell execution is unavoidable, use a well-tested platform-specific escaping mechanism for every dynamic argument.
  • Add security tests using embedded quotation marks, command separators, backticks, dollar-sign command substitutions, newlines, and other shell metacharacters to verify that supplied content is always handled as literal data.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to sync meeting minutes to Feishu and persist action items to local memory, but it does not require explicit user consent, data minimization, or any warning that potentially sensitive meeting content will be transmitted to an external service and stored for later use. Meeting minutes commonly contain confidential business discussions, attendee identities, deadlines, and decisions, so silent export/persistence creates a real privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template explicitly states that the meeting minutes are automatically synced to Feishu, but it provides no notice, consent step, or scope limitation for transmitting potentially sensitive meeting content. Because meeting minutes often contain internal decisions, attendee identities, action items, and unresolved issues, silent syncing can cause unintended disclosure to an external platform or broader audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The description and tags emphasize Chinese usage (e.g. Chinese trigger phrases and a 'chinese' tag), and the example is only in Chinese. While not an explicit hard requirement, the skill does not state that users may choose another language, which can create an unnecessary locale bias.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

All headings, labels, and fixed text in the template are in Chinese, which indicates the skill produces output in a specific language by default. There is no visible opt-in, language selection, or justification that this template is intended only for a Chinese-language or region-specific context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.