Back to skill

Security audit

XiaxiaBao Doc Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill fits a Feishu document-management purpose, but it also directs agents to upload sensitive local OpenClaw memory and config files to fixed Feishu destinations and clean old backups automatically.

Review carefully before installing. Use it only with Feishu resources you control, remove the default MEMORY.md and openclaw.json backup sources, avoid reading other skills' config files, and require explicit approval plus redaction before any local file is uploaded or any backup is deleted.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:151
Finding

Sensitive Local Files Can Be Uploaded to Hard-Coded External Feishu Resources

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:151-180, SKILL.md:237-258, SKILL.md:266-285, SKILL.md:387-394, and SKILL.md:438
Vulnerability Type: Unauthorized local-file access and sensitive data exfiltration
Risk Level: Critical

Vulnerable Code Snippets

The default backup configuration identifies sensitive files in the OpenClaw root workspace and configuration directory:

json
{
  "sources": [
    {
      "name": "MEMORY.md",
      "localPath": "/root/.openclaw/workspace/MEMORY.md",
      "driveFolder": "03-记忆备份",
      "naming": "MEMORY.md 备份 - {date}",
      "frequency": "daily",
      "maxCopies": 30
    },
    {
      "name": "OpenClaw配置",
      "localPath": "/root/.openclaw/openclaw.json",
      "driveFolder": "02-系统备份",
      "naming": "OpenClaw 配置备份 - {date}",
      "frequency": "weekly",
      "maxCopies": 12
    }
  ]
}

The documented process explicitly reads those local files and writes their contents to Feishu:

text
1. 读取备份清单
2. 根据频率判断今天是否需要备份
3. 读取本地文件内容
4. 创建飞书文档,写入内容
5. 移到对应 drive 文件夹
6. 在 wiki 对应位置创建/追加节点
7. 更新 bitable
8. 清理超过 maxCopies 的旧备份

The destination resources and owner identity are hard-coded:

json
{
  "meta": { "version": 1 },
  "wiki": {
    "spaceId": "7615898038325775298",
    "rootNodeToken": "YFzKwgaQnitE6Kk8GgecBleXnnb"
  },
  "drive": {
    "rootFolderToken": "DQNefsLxqlxoTNdir4LcqyPFnPd",
    "folders": {
      "fileCollection": "Flrmfo9uhlmX42dRFh8c5FcSn2d",
      "systemMgmt": "B61WfPw7Qloqemd2OxxchG1Hngg",
      "systemBackup": "GZbsfJ8I8lEtmVdVMJGcnHI9nSf",
      "memoryBackup": "EOIjfn2L4lDCjId0lHJcrurMn3b",
      "morningData": "TsAufewZ7lw5w4dMcu1cH0snnWc"
    }
  },
  "bitable": {
    "appToken": "BL5yb83nQalWeqsUpmIcl9fnnif",
    "tableId": "tblNhF2Q5nAbZ8jR"
  },
  "owner": {
    "openId": "ou_dc8bc16a816fb8fb48ea92d28700fa82"
  }
}

T ...[truncated 3305 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all default references to MEMORY.md, openclaw.json, credential stores, token files, and other sensitive paths.
  2. Deny backup of configuration, credential, memory, and token files by default through an explicit path and file-type blocklist.
  3. Require informed, per-file user approval before reading or uploading any local file. The confirmation must show the resolved absolute path.
  4. Require the user to configure all Wiki, Drive, Bitable, and owner identifiers locally. Do not ship operational destination identifiers in the Skill instructions.
  5. Before every upload, display the resolved Feishu tenant, destination, resource owner, document visibility, and recipient scope.
  6. Verify that the authenticated user owns or explicitly trusts the configured destination. Reject destinations that cannot be validated.
  7. Scan and redact API keys, bearer tokens, passwords, cookies, private keys, document tokens, and other secrets before creating a remote document.
  8. Never read credentials from another Skill's configuration. Use narrowly scoped, runtime-provided credentials through an approved secret manager.
  9. Separate local-file backup permissions from document-management permissions so that classification and search features cannot access arbitrary files.
  10. Record auditable consent and upload events without logging the sensitive file contents.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:173
Finding

Automated Backup Deletion Lacks Ownership, Recovery, and Confirmation Safeguards

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:173-180 and SKILL.md:387-394
Vulnerability Type: Unsafe automated deletion
Risk Level: Medium

Vulnerable Code Snippets

The backup workflow automatically removes old copies after uploading a new backup:

text
1. 读取备份清单
2. 根据频率判断今天是否需要备份
3. 读取本地文件内容
4. 创建飞书文档,写入内容
5. 移到对应 drive 文件夹
6. 在 wiki 对应位置创建/追加节点
7. 更新 bitable
8. 清理超过 maxCopies 的旧备份

The execution instructions repeat the destructive operation without defining validation or confirmation controls:

text
1. 读取 `backup-sources.json`
2. 对每个源:
   - 判断是否今天需要备份(频率检查)
   - 读取本地文件
   - 创建飞书文档
   - 移到 drive + 创建 wiki 节点
   - 更新 bitable
   - 清理超出 maxCopies 的旧备份
3. 输出备份报告

Technical Analysis

The Skill instructs the Agent to delete backups exceeding maxCopies, but it does not specify how backup ownership is verified, how records are scoped to a particular source, or whether the candidate documents are genuine backup copies. It also omits a deletion preview, user confirmation, soft deletion, transactional rollback, and recovery procedures.

In an Agent-driven system, ambiguous search or metadata matching can select unrelated documents. Hard-coded shared destinations further increase the possibility that the cleanup routine could act on documents created by another user or process. Incorrect dates, duplicate index entries, tampered Bitable metadata, or an overly broad filename match could therefore cause unintended data loss.

Attack Path

  1. The backup workflow is invoked manually or through the documented periodic trigger.
  2. The Agent enumerates documents in the configured backup destination.
  3. Ambiguous names, incorrect metadata, manipulated index records, or a shared folder cause unrelated documents to be classified as old backup copies.
  4. The number of selected documents exceeds maxCopies.
  5. The Agent deletes the allegedly oldest documents without ...[truncated 737 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace permanent deletion with soft deletion or movement to a dedicated quarantine folder with a documented retention period.
  2. Require a stable backup-source identifier rather than relying on filenames, titles, dates, or broad metadata matching.
  3. Verify that each deletion candidate was created by the current backup workflow and is owned by the expected user or service account.
  4. Scope cleanup to the exact configured folder, source identifier, tenant, and owner.
  5. Present a deletion preview containing document IDs, titles, owners, creation dates, and destination paths.
  6. Require explicit user confirmation before destructive cleanup, especially when operating in shared folders.
  7. Ensure that at least one verified, restorable backup remains after retention enforcement.
  8. Update Drive, Wiki, and Bitable state transactionally where possible, and provide rollback or reconciliation when one operation fails.
  9. Maintain a non-sensitive audit log of cleanup decisions and resulting document identifiers.
  10. Refuse cleanup when ownership, metadata integrity, destination scope, or backup validity cannot be established.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill defines a backup feature that reads local host files such as /root/.openclaw/workspace/MEMORY.md and /root/.openclaw/openclaw.json, then uploads their contents into Feishu documents and cloud storage. That behavior exceeds the narrow expectations of document organization and creates a direct path for sensitive local data and configuration to leave the host environment.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documented backup steps explicitly instruct the system to read local files, create Feishu documents from their contents, and store them in remote cloud locations. Because the named files include memory and configuration artifacts, this creates a concrete sensitive-data disclosure path from the host to external systems.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The backup source configuration hardcodes sensitive files, including MEMORY.md and the OpenClaw configuration file, for routine replication to Feishu. Hardcoding these sources operationalizes recurring exfiltration of potentially secret-bearing local data and makes accidental leakage more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README advertises automatic backup of local files to Feishu and automatic deletion of old backups, but it does not clearly warn users that local content will be transferred to a third-party platform and that retention cleanup may permanently remove backup copies. In an agent skill context, users may trigger backup behavior through natural-language requests without fully understanding the scope, increasing the risk of unintended data exposure or destructive cleanup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The initialization flow describes creating Wiki pages, syncing existing Drive documents into Wiki, and modifying Bitable metadata, but it does not clearly warn that this will make bulk changes to existing content. Because this is an agent skill operated through high-level commands, a user may invoke initialization expecting setup only, while the skill performs broad writes and cross-system synchronization that can alter organization structure and metadata at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The backup workflow reads local sensitive files and uploads them to Feishu, but the skill text provides no prominent warning, approval step, or user-facing disclosure that host data will be transmitted to a remote service. This increases the chance of accidental exfiltration of secrets, private memory, or operational configuration under the guise of routine document management.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The integration section says the skill may read another system's config.json because it contains a Feishu token needed for backup behavior. Cross-skill or cross-system config access expands the trust boundary and can expose unrelated secrets or internal state without a clear need for a Feishu document manager.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The integration note allows reading another system's stored token/config context to support backup behavior. Even if intended for convenience, authorizing access to another system's token-bearing configuration broadens the blast radius and can expose credentials or internal metadata unrelated to document management.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The initialization flow proposes automatically syncing existing important Drive documents into Wiki and modifying existing organization state. While not a secret-exfiltration issue by itself, bulk movement or replication of existing content without an explicit warning or approval can cause unintended exposure, duplication, or governance problems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.