Back to skill

Security audit

AI工作日记

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent Feishu journaling purpose, but it can write to a remote workspace from broad triggers and its promised local config git protection is missing.

Install only if you are comfortable with the skill creating Feishu documents under your logged-in account. Before use, add an ignore rule for config.local.json or store the config outside the repository, and require explicit confirmation before each publish when the request does not clearly say to publish to Feishu.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:123
Finding

Private Feishu Configuration Is Not Protected from Git Commits

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 123–142
Vulnerability Type: Sensitive configuration exposure caused by a missing .gitignore rule
Risk Level: Medium

Vulnerable Code Snippet

markdown
征得用户同意后,把落库目标写到本 skill 目录下的本地文件(已加入 `.gitignore`):

```text
config.local.json

示例(占位符,勿提交真实值):

json
{
  "parent_wiki_url": "https://xxx.feishu.cn/wiki/<YOUR_NODE_TOKEN>",
  "parent_node_token": "<YOUR_NODE_TOKEN>",
  "preferred_tool": "mcp",
  "title_timezone": "Asia/Shanghai"
}
  • 读:有文件则解析;无效或缺字段则重新询问
  • 写:仅在用户确认「记住」后更新
  • 禁止把 config.local.json 提交到 git 或贴进公开 Issue
text

The same inaccurate assurance also appears in `README.md`, line 7:

```markdown
本仓库**不含**任何私有 Wiki 链接或 token;首次使用由 Agent 询问落库位置,可征得你同意后写入本机 `config.local.json`(已 gitignore)。

Technical Analysis

The Skill instructs the Agent to persist a real Feishu parent Wiki URL and node token in config.local.json. It states that this file is already protected by .gitignore, but the audited project contains only README.md, SKILL.md, and config.local.example.json. No .gitignore file or equivalent exclusion rule is present.

Consequently, the documented security control does not exist. If the Agent creates config.local.json in the repository, ordinary commands such as git add . can stage it without warning.

The node token is presented as a resource identifier rather than an authentication secret, so this issue does not independently establish account compromise. Nevertheless, disclosure can reveal private Wiki URLs, internal knowledge-base locations, tenant information, and document hierarchy. The leaked identifier could also assist targeted access attempts when combined with separately obtained credentials or an authenticated session.

Attack Path

  1. A user invokes the Skill and supplies a private Feishu Wiki URL or parent node token.
  2. The user authorizes the Skill to remember that destination.
  3. Following SKILL.md, the Agent writes t ...[truncated 1005 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add a repository-root .gitignore file containing an explicit root-level exclusion:

    gitignore
    /config.local.json
    
  2. Verify the protection with:

    bash
    git check-ignore -v config.local.json
    
  3. Before writing the local configuration, have the Skill verify that the target path is ignored. If it is not, warn the user and avoid storing the values in the repository.

  4. Prefer a user-specific configuration directory outside the Git working tree, with restrictive filesystem permissions, rather than storing private location metadata in the Skill directory.

  5. Store only the minimum data required. Avoid retaining the full Wiki URL when the parent node identifier alone is sufficient.

  6. Add a pre-commit or CI check that rejects real Feishu Wiki URLs, node tokens, credentials, and config.local.json.

  7. Update README.md and SKILL.md so they claim Git exclusion only after the corresponding .gitignore rule is actually shipped and verified.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README suggests activating the skill with natural phrases like「记到飞书知识库 / 写今天的 AI工作日记」, but it does not define exact trigger boundaries, exclusions, or negative examples. These phrases are common enough in normal conversation that they could overlap with everyday requests and cause unintended invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes broad natural-language phrases such as '每天用 AI' and '写今天的记录', which can match ordinary conversation that is not actually requesting publication to Feishu. This can cause unintended activation of a skill that writes content to an external knowledge base, creating privacy and integrity risks if drafts or sensitive work summaries are published without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The read_when conditions are generic and ambiguous, for example '写 AI工作日记' and '排障 / 提效 / 探索记录落库', without strong scoping to Feishu publishing. Because this skill can create remote documents and reuse locally remembered destinations, broad activation conditions increase the chance of invoking the skill in contexts where the user only wanted drafting help, not external publication.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The JSON example sets title_timezone to Asia/Shanghai, which is a locale-specific default expressed in natural language configuration. Under the policy rules, forcing a specific locale without user opt-in or documented justification can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.