Back to skill

Security audit

飞书日历管理

Security checks for vulnerabilities and agentic risk

Overview

This Feishu calendar skill is purpose-aligned, but it asks users to store reusable OAuth credentials in plaintext and documents calendar deletion without explicit confirmation guardrails.

Review this skill before installing. Only use it if you are comfortable granting Feishu calendar read/write/delete permissions, and protect or replace the documented plaintext token file with a secure credential store or strict user-only permissions. Confirm event details before allowing updates or deletions, and revoke or rotate the Feishu app credentials if the token file may have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/oauth-setup.md:127
Finding

OAuth Credentials Stored in an Unprotected Plaintext JSON File

Content
View full analysis

Vulnerability Details

File Location: references/oauth-setup.md:127-140; related token-refresh logic in SKILL.md:54-62
Vulnerability Type: Plaintext storage of reusable OAuth credentials
Risk Level: Medium

Vulnerable Code

references/oauth-setup.md:127-140:

powershell
# 保存配置
$config = @{
    access_token = $resp2.data.access_token
    refresh_token = $resp2.data.refresh_token
    calendar_id = $calendarId
    app_id = $appId
    app_secret = $appSecret
}
$tokenFile = "$env:USERPROFILE\.openclaw\workspace\skills\feishu-calendar-oauth\scripts\.user_token.json"
New-Item -ItemType Directory -Force -Path (Split-Path $tokenFile) | Out-Null
$config | ConvertTo-Json | Out-File $tokenFile -Encoding UTF8

SKILL.md:54-62:

powershell
# 刷新 Token
$config = Get-Content "$env:USERPROFILE\.openclaw\workspace\skills\feishu-calendar-oauth\scripts\.user_token.json" | ConvertFrom-Json
$body1 = @{ app_id = $config.app_id; app_secret = $config.app_secret } | ConvertTo-Json
$appToken = (Invoke-RestMethod -Uri "https://open.feishu.cn/open-apis/auth/v3/app_access_token/internal" -Method Post -Body $body1 -ContentType "application/json").app_access_token
$body2 = @{ grant_type = "refresh_token"; refresh_token = $config.refresh_token } | ConvertTo-Json
$newToken = Invoke-RestMethod -Uri "https://open.feishu.cn/open-apis/authen/v1/oidc/refresh_access_token" -Method Post -Body $body2 -ContentType "application/json" -Headers @{ Authorization = "Bearer $appToken" }
$config.access_token = $newToken.data.access_token
$config.refresh_token = $newToken.data.refresh_token
$config | ConvertTo-Json | Out-File "$env:USERPROFILE\.openclaw\workspace\skills\feishu-calendar-oauth\scripts\.user_token.json"

Technical Analysis

The documented setup procedure stores the Feishu application secret, access token, refresh token, calendar identifier, and application identifier in an ordinary JSON file. T ...[truncated 2407 chars]

Remediation
View remediation

Remediation Suggestions

  1. Store the App Secret and OAuth refresh token in an operating-system-backed secret store, such as Windows Credential Manager or a DPAPI-protected credential container, rather than in the workspace.
  2. Avoid retaining the App Secret in the calendar configuration file when it is not required for normal calendar operations.
  3. If file storage is unavoidable, encrypt sensitive values with DPAPI under the current user context and decrypt them only in memory when needed.
  4. Create the credential file with an explicit current-user-only ACL. Do not rely solely on inherited directory permissions.
  5. Use atomic replacement with restrictive permissions during token refresh so that rewrites do not temporarily create a broadly readable file or weaken the existing ACL.
  6. Add .user_token.json to version-control, packaging, backup, logging, and workspace-synchronization exclusion rules.
  7. Document credential revocation and rotation procedures. Users should revoke the refresh token and rotate the App Secret if the file may have been exposed.
  8. Store non-sensitive data such as calendar_id separately from secrets to minimize the contents of the protected credential store.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises very broad trigger conditions such as asking about 'today/tomorrow/some day schedules', creating meetings, deleting events, and viewing calendar plans, which overlap heavily with normal assistant conversations. This can cause the skill to activate unexpectedly on ambiguous user requests and perform or prepare calendar actions in contexts where the user did not explicitly intend to invoke this specific OAuth-backed integration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide provides a ready-to-run deletion example for calendar events without any cautionary note, confirmation guidance, or guardrails around destructive actions. In an agent skill context, this increases the chance that downstream implementers expose deletion behavior without explicit user confirmation, leading to accidental or unauthorized loss of calendar data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs users to persist highly sensitive OAuth material locally, including the access token, refresh token, App ID, and App Secret, in a predictable plaintext JSON file under the user profile. This increases the risk of credential theft from local malware, backups, shared workstations, or accidental disclosure, and the document does not warn users about secure storage, file permissions, or secret rotation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file's natural-language instructions and headings are all in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language. The policy specifically calls out forced language or locale without user opt-in as a violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes calendar management as querying schedules, creating/updating/deleting events, setting recurrence, and viewing calendar arrangements. This guide additionally documents use of the separate free/busy API, which exposes availability status rather than event CRUD behavior explicitly described in the manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

All user-facing instructions in this skill file are presented only in Chinese, which effectively forces a specific language without user opt-in. Under the stated policy, locale or language constraints should either offer user choice or be explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.