Back to skill

Security audit

飞书文档

Security checks for vulnerabilities and agentic risk

Overview

This skill is mainly a Feishu document reader, but it asks for broad read/write/exec authority and documents unrelated command, file, and messaging capabilities without clear controls.

Review before installing. Use only if you are comfortable granting this skill broad read/write/exec capability and Feishu document access. Prefer a version limited to explicit Feishu URL retrieval with no generic command execution, no unrelated messaging features, and a clear privacy notice for document content and tokens.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Description-Behavior Mismatch

High
Confidence
94% confidence
Finding
The skill is presented as a Feishu document retrieval tool, but this section advertises unrelated capabilities such as bulk message sending, template injection, callbacks, and communication archival. That scope expansion is dangerous because it conditions users and agents to expect broader authority than necessary, increasing the chance the skill is invoked in contexts involving outbound messaging or sensitive workflow actions not justified by its stated purpose.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
This section advertises generic file processing, command execution, and information retrieval capabilities that materially exceed a document-fetching skill's declared function. Overbroad capability claims are risky because they can justify unnecessary use of write/exec privileges and make it easier to hide harmful behavior behind an otherwise benign Feishu-reader description.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Documenting command execution for a Feishu document reader is unjustified and creates a direct avenue for misuse, especially since the manifest includes exec. In this context, exec is more dangerous because the skill's legitimate task is API-based content retrieval, so shell access is unnecessary and could be abused for arbitrary local actions or data access.

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
The startup guidance tells users to execute commands and troubleshoot command failures even though the skill's stated purpose is Feishu content fetching. That normalizes command use as part of routine operation, which can lead agents or users to grant and use unnecessary execution privileges, broadening the attack surface beyond simple document retrieval.

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The document repeatedly frames the skill as a Feishu document fetcher, then later introduces generic exec and file-processing abilities that contradict that narrow purpose. This inconsistency is dangerous because it obscures the true operational scope, making risky permissions appear acceptable under the cover of a simple content-retrieval tool.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation guidance is overly broad, tying use of the skill to generic writing, marketing, and content-creation tasks rather than specifically to cases where a Feishu URL or token must be fetched. In an agent setting, broad triggers increase unintended invocation and may cause unnecessary transmission of workspace document identifiers and content to external APIs.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The description does not clearly warn users that provided Feishu URLs/tokens and retrieved content will be sent to Feishu APIs and processed externally. For a document-access skill, this omission matters because users may unknowingly expose internal document metadata or contents, especially in enterprise environments where Feishu pages can contain sensitive information.

Static analysis

No suspicious patterns detected.