T05 · Unauthorized Access and Privilege Escalation
- Location
index.js:130- Finding
Feishu bot access is open to all senders by default
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to configure Feishu bots as claimed, but its default public access setting and credential handling create review-worthy risk.
Install only if you intend to let this skill modify your live OpenClaw Feishu configuration. Before running it, avoid putting real App Secrets directly in shell history, review the generated ~/.openclaw/openclaw.json, prefer pairing or allowlist over open access, and confirm the bound Agent does not expose sensitive tools or data to untrusted Feishu users.
index.js:130Feishu bot access is open to all senders by default
index.js:199Feishu App Secret is accepted through command-line arguments
index.js:106Security-sensitive configuration values are written without validation
package.json:10Unused third-party readline package creates avoidable supply-chain exposure
The skill handles configuration changes involving Feishu credentials and appears to require environment/code capabilities, but it declares no explicit tool scope or permissions boundary. That increases the risk of overbroad execution privileges, making it harder for operators to understand or constrain what the skill may access when processing sensitive bot setup data.
The skill explicitly asks users for an App Secret and stores it in configuration examples, but it does not warn about secure handling, masking, storage protection, or access control. This creates a real credential-exposure risk because operators may enter secrets into chat logs or persist them in plaintext configuration and backups.
The skill description and user-facing interface are written in Chinese, and the file does not provide an opt-in, alternative language, or justification for restricting operation to that locale. This creates a language/locale policy concern because users are forced into a specific language without explicit choice.
Comments and user-visible validation error strings are written exclusively in Chinese, including messages returned to callers such as '缺少 channels.feishu 配置' and 'App Secret 不能为空'. This imposes a specific language on downstream users or operators without any opt-in, fallback, or justification for a locale-specific deployment.
The dependency is specified with a caret range (^1.3.0), which allows automatic installation of newer compatible versions instead of a single vetted release. This increases supply-chain risk because a compromised or breaking upstream release could be pulled in without explicit review, though the impact here is limited because the package is a common dependency and no additional suspicious context is present in this file.
"start": "node index.js"
},
"dependencies": {
"readline": "^1.3.0"
}
}
Detected: suspicious.dangerous_exec