Back to skill

Security audit

Feishu Doc Summarizer

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it automatically reads full Feishu/Lark documents and consults persistent memory without clear confirmation or tight scoping.

Review before installing if your Feishu/Lark documents or agent memory may contain sensitive information. Use it only when you are comfortable with linked documents being read in full and summarized into the current chat, and keep the memory-stored summary template free of unrelated private details.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:36
Finding

Persistent Memory Access Exceeds the Document-Summarization Data Boundary

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is designed to read the full contents of a Feishu/Lark document and post a derived summary back into the current chat, but it does not require an explicit confirmation step or present a privacy warning before accessing potentially sensitive document data. This can lead to unintentional disclosure of confidential content, especially when the user shares a link casually or the current chat has a broader audience than the source document.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.