Back to skill

Security audit

Feishu Bot Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to configure Feishu bots as claimed, but its default public access setting and credential handling create review-worthy risk.

Install only if you intend to let this skill modify your live OpenClaw Feishu configuration. Before running it, avoid putting real App Secrets directly in shell history, review the generated ~/.openclaw/openclaw.json, prefer pairing or allowlist over open access, and confirm the bound Agent does not expose sensitive tools or data to untrusted Feishu users.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
index.js:130
Finding

Feishu bot access is open to all senders by default

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:199
Finding

Feishu App Secret is accepted through command-line arguments

Content
View full analysis
飞书 App ID (必填) --app-secret 飞书 App Secret (必填) ``` ### Technical Analysis Command-line arguments are not an appropriate transport for long-lived credentials. Depending on the operating system and execution environment, arguments may be exposed through process inspection, shell history, terminal logging, job telemetry, debugging records, or orchestration logs. Although the code does not print the App Secret directly, it reads the value from `process.argv`. Exposure can therefore occur before or independently of the Skill's own logging behavior. ### Attack Path 1. An administrator follows the documented command and supplies the App Secret using `--app-secret`. 2. The shell records the command in history, or the running process exposes its arguments to process-monitoring facilities. 3. A local user, support operator, monitoring service, or log consumer reads the recorded arguments. 4. The observer extracts the Feishu App Secret. 5. The exposed credential ...[truncated 389 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:106
Finding

Security-sensitive configuration values are written without validation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
package.json:10
Finding

Unused third-party readline package creates avoidable supply-chain exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
78% confidence
Finding

The skill handles configuration changes involving Feishu credentials and appears to require environment/code capabilities, but it declares no explicit tool scope or permissions boundary. That increases the risk of overbroad execution privileges, making it harder for operators to understand or constrain what the skill may access when processing sensitive bot setup data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly asks users for an App Secret and stores it in configuration examples, but it does not warn about secure handling, masking, storage protection, or access control. This creates a real credential-exposure risk because operators may enter secrets into chat logs or persist them in plaintext configuration and backups.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and user-facing interface are written in Chinese, and the file does not provide an opt-in, alternative language, or justification for restricting operation to that locale. This creates a language/locale policy concern because users are forced into a specific language without explicit choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Comments and user-visible validation error strings are written exclusively in Chinese, including messages returned to callers such as '缺少 channels.feishu 配置' and 'App Secret 不能为空'. This imposes a specific language on downstream users or operators without any opt-in, fallback, or justification for a locale-specific deployment.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a caret range (^1.3.0), which allows automatic installation of newer compatible versions instead of a single vetted release. This increases supply-chain risk because a compromised or breaking upstream release could be pulled in without explicit review, though the impact here is limited because the package is a common dependency and no additional suspicious context is present in this file.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
"start": "node index.js"
  },
  "dependencies": {
    "readline": "^1.3.0"
  }
}

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:169