Back to skill

Security audit

Minutes Sync

Security checks for vulnerabilities and agentic risk

Overview

This meeting-minutes skill is coherent but needs Review because it automatically sends meeting content to Feishu and gives unsafe shell-command examples using user-controlled meeting data.

Install only if you want meeting minutes synced to Feishu by default. Confirm the destination, recipients, and document permissions before syncing confidential meetings, and avoid using the shown bash commands with raw meeting titles, Markdown, or document IDs unless they are passed through a safe argument API rather than shell interpolation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:35
Finding

Command Injection Through Unsafe Shell Interpolation

Content
View full analysis
" ``` `references/feishu-sync.md:6`: ```bash python3 .claude/skills/feishu-doc/scripts/doc_ctl.py create "会议纪要 - {{title}} - {{date}}" --content "" ``` `references/feishu-sync.md:12`: ```bash python3 .claude/skills/feishu-doc/scripts/doc_ctl.py append "追加内容" ``` `references/feishu-sync.md:18`: ```bash python3 .claude/skills/feishu-doc/scripts/doc_ctl.py replace --section "决议事项" "## 决议事项\n新内容" ``` ### Technical Analysis The documented workflow places dynamic meeting titles, dates, rendered Markdown, document identifiers, and replacement or appended content directly into shell command strings. These values can originate from untrusted meeting notes, transcripts, or direct user input. If the agent constructs and executes the examples through a shell, an attacker can terminate the intended quoted argument or use shell evaluation features such as command substitution. Double quotes do not prevent constructs such as `$(command)` from being evaluated. Unquoted placeholders such as `` are additionally exposed to shell metacharacter interpretation and argument injection. Quoting alone is not a reliable fix because shell evaluation rules are complex and meeting content can contain arbitrary Markdown, quotation marks, substitutions, and line breaks. The implementation of the referenced `doc_ctl.py` script is not included in the audited project. Consequently, this finding concerns the unsafe command-construction instructions in the supplied skill rather ...[truncated 1511 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description is broad enough to trigger on generic note-taking, summarization, or meeting-related requests, which increases the chance the skill activates in contexts where the user did not explicitly ask for Feishu-backed minute generation. Because this skill also performs external sync, overbroad routing can cause unintended handling and disclosure of sensitive meeting content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises automatic Feishu synchronization but does not clearly warn that meeting content may be sent to an external collaboration platform. Meeting minutes often contain confidential internal discussions, attendees, decisions, and deadlines, so silent or assumed syncing creates a meaningful data disclosure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow directs the agent to return a Feishu link to participants without any guardrails around access control, sharing scope, or whether those participants are authorized to receive the document. In practice, this can expose sensitive meeting notes through overly permissive document sharing or accidental disclosure of the link.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire template is written in Chinese, including the title, section headings, status text, and footer, which imposes a specific language/locale on generated output. There is no visible opt-in, alternative language option, or documentation that this skill is intended only for a Chinese-language or region-specific context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.