T09 · Insecure Skill Coding Practices
- Location
scripts/upload_to_feishu.cjs:19- Finding
Hardcoded Feishu Application Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its stated publishing purpose, but it includes hardcoded Feishu credentials and can upload user-generated content to Feishu under unclear account control.
Review before installing. Do not use the bundled Feishu credentials; require the publisher to remove and rotate the exposed secret, then configure your own least-privilege Feishu app credentials. Render only trusted generated HTML, ideally with JavaScript and outbound network disabled, and pin the Playwright/browser dependency versions.
scripts/upload_to_feishu.cjs:19Hardcoded Feishu Application Credentials
SKILL.md:72Unpinned Third-Party Package and Browser Installation
scripts/render_images.py:11Untrusted HTML Rendered with JavaScript and Unrestricted Network Access
The skill embeds a Feishu appId, appSecret, and owner open_id directly in the documentation. Hard-coded credentials are highly sensitive secrets; anyone with access to the skill can reuse them to authenticate to Feishu APIs, read or modify documents, or impersonate the configured integration depending on its privileges.
The script contains concrete fallback values for FEISHU_APP_ID, FEISHU_APP_SECRET, and FEISHU_OWNER_ID directly in source code. This is dangerous because anyone who runs the skill without overriding environment variables may unknowingly authenticate against a fixed Feishu app and create documents under a specific account, causing credential exposure and data exfiltration to an unintended tenant.
Using hardcoded Feishu credentials and an owner ID as silent fallbacks means the script can perform remote API actions even when the operator did not intend to supply credentials. In this skill context, the script processes user-provided document-derived content and images, so those materials may be uploaded into a fixed external workspace without the user's informed consent.
The hardcoded credential and owner fallback can direct generated documents and uploaded local content into a predetermined Feishu workspace controlled by someone other than the operator. Because this skill handles converted document text, summaries, and images, the issue materially increases the risk of unintended disclosure of potentially sensitive or proprietary content.
The skill performs document reads, local file generation, and upload-related actions, but it does not declare any explicit tool scope or allowed-tools boundary. That omission weakens reviewability and increases the chance that an agent can access files or perform side effects beyond what a user expects from a publishing workflow.
The description and outputs are entirely specified in Chinese and tailored to Xiaohongshu-style Chinese content, but the file does not state that this is a China-specific or Chinese-only skill nor offer opt-in for language selection. This can violate language/locale policy when a skill implicitly forces a specific language without user choice.
The skill creates local output files and uploads content into Feishu documents, but it does not prominently warn users that it will write files and create/modify remote documents. In an agent setting, undisclosed side effects can lead to unauthorized publication, accidental data propagation, or modification of user content without fully informed consent.
These API calls send the contents of local image files to Feishu, and later code also sends markdown content from a local file. While logs indicate progress, there is no clear safety/privacy disclosure warninging users that files from the provided directory and summary file will be transmitted off-machine to a remote document service.
The template sets the document language to Chinese using lang="zh", which is a natural-language locale choice applied globally to the content. There is no indication in the file that this locale restriction is optional, user-selected, or justified as region-specific, so it may violate language/locale policy requirements.
The markdown includes a specific Chinese font choice, "PingFang SC," in a prescriptive design style recommendation. Because the document is otherwise framed as general design guidance rather than explicitly China-only or opt-in locale guidance, this can be interpreted as forcing a locale-specific presentation choice without user selection.
The docstring and all user-facing CLI messages are written in Chinese, which imposes a specific language on users without any opt-in or alternative locale support. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation.
No suspicious patterns detected.