Back to skill

Security audit

Feishu Bot Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill’s bot-management purpose is real, but it has review-worthy risks around open bot access, plaintext secrets, backups, and unsafe directory deletion paths.

Review this skill carefully before installing. Use it only in an environment where the OpenClaw config and backups are protected, rotate any secrets that may have appeared in shell history, restrict bot access after creation, and avoid untrusted or path-like botId values until validation is added.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/feishu-bot.sh:145
Finding

Unvalidated Bot Identifier Enables Path Traversal and Recursive Deletion

Content
View full analysis
" exit 1 fi check_prerequisites # Check if bot exists if ! bot_exists "$bot_id"; then print_error "Bot '$bot_id' not found!" exit 1 fi backup_config # Define paths local workspace_path="$HOME/.openclaw/workspace-$bot_id" local agent_dir="$HOME/.openclaw/agents/$bot_id" # Modify config using jq local tmp_file=$(mktemp) jq --arg bot_id "$bot_id" ' .agents.list = [.agents.list[]? | select(.id != $bot_id)] | .channels.feishu.accounts = del(.channels.feishu.accounts[$bot_id]) | .bindings = [.bindings[]? | select(.agentId != $bot_id)] ' "$OPENCLAW_CONFIG" > "$tmp_file" mv "$tmp_file" "$OPENCLAW_CONFIG" # Remove directories (ask first) if [[ -d "$workspace_path" || -d "$agent_dir" ]]; then echo "" read -p "Delete workspace and agent directories? [y/N] " -n 1 -r echo if [[ $REPLY =~ ^[Yy]$ ]]; then rm -rf "$workspace_path" "$agent_dir" ``` The same unvalidated identifier is used when creating directories: ```bash local workspace_path="$HOME/.openclaw/workspace-$bot_id" local agent_dir="$HOME/.openclaw/agents/$bot_id/agent" mkdir -p "$workspace_path" "$agent_dir" ``` ### Technical Analysis The user-controlled `bot_id` is incorporated directly into filesystem paths without format validation or canonical containment checks. Shell quoting prevents word splitting and shell metacharacter injection, but it does not prevent path traversal through values containing `../`. For example, a ...[truncated 1745 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/feishu-bot.sh:109
Finding

New Feishu Bots Are Configured for Unrestricted Access

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/feishu-bot.sh:58
Finding

Feishu Application Secrets Are Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/feishu-bot.sh:35
Finding

Secret-Bearing Configuration Backups Accumulate Without Explicit Protection or Retention

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly supports adding and updating Feishu app credentials and deleting bot configurations, but it provides no warning, confirmation, masking, or handling guidance for sensitive secrets and destructive operations. In an agent setting, this increases the chance of accidental credential exposure in chat/logs and unintended destructive configuration changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The backup routine copies the entire OpenClaw configuration, including any embedded Feishu credentials, to an additional file, increasing the number of plaintext secret copies on disk. This broadens the attack surface because secret exposure can occur through stale backups, weaker permissions, backup tooling, or accidental sharing of backup files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The add flow persists Feishu app credentials directly into the user's OpenClaw JSON config, which creates a plaintext-at-rest secret exposure risk if the file is readable by other local users, synced, backed up, or accidentally committed. In the context of a bot-management skill, storing credentials may be functionally expected, but doing so without an explicit warning or safer secret-handling option still exposes sensitive authentication material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The update path writes a replacement app secret into the config file without notifying the user that the new credential will be stored persistently in plaintext. This is dangerous because rotated or newly issued secrets may be assumed transient by operators, but instead become recoverable from disk, backups, and any process or user with access to the config.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.