Back to skill

Security audit

Feishu → XHS Publisher

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated publishing purpose, but it includes hardcoded Feishu credentials and can upload user-generated content to Feishu under unclear account control.

Review before installing. Do not use the bundled Feishu credentials; require the publisher to remove and rotate the exposed secret, then configure your own least-privilege Feishu app credentials. Render only trusted generated HTML, ideally with JavaScript and outbound network disabled, and pin the Playwright/browser dependency versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/upload_to_feishu.cjs:19
Finding

Hardcoded Feishu Application Credentials

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:72
Finding

Unpinned Third-Party Package and Browser Installation

Content
View full analysis
Remediation
View remediation
--hash=sha256: ``` 3. Generate and verify hashes for all required Python distributions and transitive dependencies. 4. Pin and pre-approve the corresponding Chromium build used by that Playwright release. 5. Fetch packages and browser binaries through an authenticated internal mirror or controlled artifact repository. 6. Build a versioned container image containing the reviewed dependencies, scan it, and distribute the immutable image instead of installing dependencies at runtime. 7. Run installation and rendering as an unprivileged account with no unnecessary secrets mounted. 8. Monitor dependency advisories and update pinned versions through a reviewed release process. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_images.py:11
Finding

Untrusted HTML Rendered with JavaScript and Unrestricted Network Access

Content
View full analysis
`, active elements, remote images, stylesheets, fonts, frames, or other network-capable resources can execute browser-side logic and initiate outbound requests during rendering. `wait_until="networkidle"` may further wait for attacker-controlled network activity rather than preventing it. The Skill's workflow creates cards from externally sourced document content. If untrusted source content is copied into HTML without strict escaping, or if an attacker can place an HTML file in the card directory, that content reaches this active rendering sink. Chromium's browser sandbox limits ordinary page scripts ...[truncated 1843 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill embeds a Feishu appId, appSecret, and owner open_id directly in the documentation. Hard-coded credentials are highly sensitive secrets; anyone with access to the skill can reuse them to authenticate to Feishu APIs, read or modify documents, or impersonate the configured integration depending on its privileges.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script contains concrete fallback values for FEISHU_APP_ID, FEISHU_APP_SECRET, and FEISHU_OWNER_ID directly in source code. This is dangerous because anyone who runs the skill without overriding environment variables may unknowingly authenticate against a fixed Feishu app and create documents under a specific account, causing credential exposure and data exfiltration to an unintended tenant.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Using hardcoded Feishu credentials and an owner ID as silent fallbacks means the script can perform remote API actions even when the operator did not intend to supply credentials. In this skill context, the script processes user-provided document-derived content and images, so those materials may be uploaded into a fixed external workspace without the user's informed consent.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The hardcoded credential and owner fallback can direct generated documents and uploaded local content into a predetermined Feishu workspace controlled by someone other than the operator. Because this skill handles converted document text, summaries, and images, the issue materially increases the risk of unintended disclosure of potentially sensitive or proprietary content.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill performs document reads, local file generation, and upload-related actions, but it does not declare any explicit tool scope or allowed-tools boundary. That omission weakens reviewability and increases the chance that an agent can access files or perform side effects beyond what a user expects from a publishing workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description and outputs are entirely specified in Chinese and tailored to Xiaohongshu-style Chinese content, but the file does not state that this is a China-specific or Chinese-only skill nor offer opt-in for language selection. This can violate language/locale policy when a skill implicitly forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill creates local output files and uploads content into Feishu documents, but it does not prominently warn users that it will write files and create/modify remote documents. In an agent setting, undisclosed side effects can lead to unauthorized publication, accidental data propagation, or modification of user content without fully informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

These API calls send the contents of local image files to Feishu, and later code also sends markdown content from a local file. While logs indicate progress, there is no clear safety/privacy disclosure warninging users that files from the provided directory and summary file will be transmitted off-machine to a remote document service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template sets the document language to Chinese using lang="zh", which is a natural-language locale choice applied globally to the content. There is no indication in the file that this locale restriction is optional, user-selected, or justified as region-specific, so it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The markdown includes a specific Chinese font choice, "PingFang SC," in a prescriptive design style recommendation. Because the document is otherwise framed as general design guidance rather than explicitly China-only or opt-in locale guidance, this can be interpreted as forcing a locale-specific presentation choice without user selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring and all user-facing CLI messages are written in Chinese, which imposes a specific language on users without any opt-in or alternative locale support. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.