T09 · Insecure Skill Coding Practices
- Location
SKILL.md:123- Finding
Private Feishu Configuration Is Not Protected from Git Commits
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 123–142
Vulnerability Type: Sensitive configuration exposure caused by a missing.gitignorerule
Risk Level: MediumVulnerable Code Snippet
markdown 征得用户同意后,把落库目标写到本 skill 目录下的本地文件(已加入 `.gitignore`): ```text config.local.json示例(占位符,勿提交真实值):
json { "parent_wiki_url": "https://xxx.feishu.cn/wiki/<YOUR_NODE_TOKEN>", "parent_node_token": "<YOUR_NODE_TOKEN>", "preferred_tool": "mcp", "title_timezone": "Asia/Shanghai" }- 读:有文件则解析;无效或缺字段则重新询问
- 写:仅在用户确认「记住」后更新
- 禁止把
config.local.json提交到 git 或贴进公开 Issue
text The same inaccurate assurance also appears in `README.md`, line 7: ```markdown 本仓库**不含**任何私有 Wiki 链接或 token;首次使用由 Agent 询问落库位置,可征得你同意后写入本机 `config.local.json`(已 gitignore)。Technical Analysis
The Skill instructs the Agent to persist a real Feishu parent Wiki URL and node token in
config.local.json. It states that this file is already protected by.gitignore, but the audited project contains onlyREADME.md,SKILL.md, andconfig.local.example.json. No.gitignorefile or equivalent exclusion rule is present.Consequently, the documented security control does not exist. If the Agent creates
config.local.jsonin the repository, ordinary commands such asgit add .can stage it without warning.The node token is presented as a resource identifier rather than an authentication secret, so this issue does not independently establish account compromise. Nevertheless, disclosure can reveal private Wiki URLs, internal knowledge-base locations, tenant information, and document hierarchy. The leaked identifier could also assist targeted access attempts when combined with separately obtained credentials or an authenticated session.
Attack Path
- A user invokes the Skill and supplies a private Feishu Wiki URL or parent node token.
- The user authorizes the Skill to remember that destination.
- Following
SKILL.md, the Agent writes t ...[truncated 1005 chars]
- Remediation
View remediation
Remediation Suggestions
-
Add a repository-root
.gitignorefile containing an explicit root-level exclusion:gitignore /config.local.json -
Verify the protection with:
bash git check-ignore -v config.local.json -
Before writing the local configuration, have the Skill verify that the target path is ignored. If it is not, warn the user and avoid storing the values in the repository.
-
Prefer a user-specific configuration directory outside the Git working tree, with restrictive filesystem permissions, rather than storing private location metadata in the Skill directory.
-
Store only the minimum data required. Avoid retaining the full Wiki URL when the parent node identifier alone is sufficient.
-
Add a pre-commit or CI check that rejects real Feishu Wiki URLs, node tokens, credentials, and
config.local.json. -
Update
README.mdandSKILL.mdso they claim Git exclusion only after the corresponding.gitignorerule is actually shipped and verified.
-
