T09 · Insecure Skill Coding Practices
- Location
scripts/audit_feishu.py:18- Finding
Hardcoded Feishu Application Secret and Fixed Recipient Identity
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This security-audit skill is mostly purpose-aligned, but it ships hardcoded Feishu credentials and can send sensitive audit details to a fixed external recipient without deployment-specific control.
Install only after removing and rotating the embedded Feishu secret, replacing all recipient IDs with deployment-owned configuration, disabling external alerts by default, adding redaction for audit details, binding confirmations to exact per-request nonces, and restricting URL scanning to safe allowed destinations.
scripts/audit_feishu.py:18Hardcoded Feishu Application Secret and Fixed Recipient Identity
scripts/audit_logger.py:73Unredacted Audit and Session Details Are Transmitted to a Hardcoded External Recipient
scripts/confirm.py:160Generic or Stale Chat Messages Can Confirm Unrelated High-Risk Operations
scripts/content_scan.py:76Arbitrary URL Fetching Bypasses the URL Guard and Permits SSRF
This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.
This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.
This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.
This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.
This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.
This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.
This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.
This finding points to two dangerous conditions: missing implementation of key defensive controls and undeclared outbound network access for alerts. In the context of an audit/protection skill, those issues are more severe because users may rely on the skill to prevent or detect abuse while it may instead expose data or silently fail to provide protection.
The script contains a hardcoded Feishu application secret directly in source code. Embedded secrets are easily leaked through source control, logs, backups, or skill distribution, allowing attackers to obtain access tokens and impersonate the application or exfiltrate audit data.
The realtime alert function immediately sends operation details to Feishu without prior confirmation, creating automatic external exfiltration of potentially sensitive security events. Because this skill is explicitly for auditing sensitive operations, the transmitted details may include confidential actions or identifiers, making the behavior more dangerous in context.
The file contains hardcoded Feishu application credentials and a fixed user identifier. Embedded secrets are highly dangerous because anyone with code or artifact access can reuse them to obtain tokens, send messages, and potentially abuse the linked tenant integration.
The script hardcodes Feishu app credentials and uses them to send and read external chat messages, creating an undisclosed outbound communication channel and exposing reusable secrets in source code. In the context of an audit/logging skill, this expands capability beyond passive logging into active external messaging and data access, which is dangerous if the code or environment is exposed or if the channel is abused for unauthorized approvals or exfiltration.
Sensitive Feishu credentials are embedded directly in the script, making them recoverable by anyone with source access, logs, backups, or accidental disclosure of the file. Once exposed, an attacker could authenticate to the external service, send messages, read chat data within granted scope, or abuse the approval workflow.
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
# 高风险模式(匹配到则触发告警)
HIGH_RISK_PATTERNS = [
(r"ignore\s+(all\s+)?(previous|prior|above)\s+(instruction|inject)", "提示词注入: ignore previous instructions"),
(r"(system|developer)\s*:\s*", "提示词注入: system/developer role"),
(r"disregard\s+(all\s+)?(previous|prior)", "提示词注入: disregard previous"),
(r"forget\s+(all\s+)?(previous|prior|instructions)", "提示词注入: forget instructions"),
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
HIGH_RISK_PATTERNS = [
(r"ignore\s+(all\s+)?(previous|prior|above)\s+(instruction|inject)", "提示词注入: ignore previous instructions"),
(r"(system|developer)\s*:\s*", "提示词注入: system/developer role"),
(r"disregard\s+(all\s+)?(previous|prior)", "提示词注入: disregard previous"),
(r"forget\s+(all\s+)?(previous|prior|instructions)", "提示词注入: forget instructions"),
(r"you\s+are\s+(now\s+)?(?:no longer|not\s+a)", "角色扮演陷阱: 解除AI身份"),
(r"(unconditional|absolute)\s+obedience", "精神控制: 无条件服从"),
The script embeds Feishu app credentials and a fixed recipient identifier directly in source code, then uses them to transmit audit-derived alerts to an external messaging service. Hardcoded secrets are easily exposed through source distribution, logs, backups, or repository access, enabling unauthorized use of the Feishu app and unintended exfiltration of operational activity data.
Hardcoded APP_ID, APP_SECRET, and USER_ID are sensitive operational identifiers used to obtain an access token and send messages. Because they are embedded and used without any user-facing disclosure, anyone with access to the code can reuse them to impersonate the application, trigger alerts, or abuse the associated Feishu integration.
The file’s behavior materially diverges from the declared audit-log skill purpose: it implements URL screening, whitelist management, and outbound messaging. This kind of capability mismatch is dangerous because operators may grant trust or permissions based on the manifest while the code performs unrelated network-policy and notification actions, increasing the chance of unnoticed data handling and policy bypass.
The script embeds Feishu application credentials and a user identifier directly in source code, enabling anyone with file access to reuse them for unauthorized API access or impersonated messaging. In the context of a purported audit tool, hidden messaging credentials are especially dangerous because they create covert outbound communication and secret-management failures at the same time.
The hard-coded Feishu credentials are actively used to request a tenant access token over the network, meaning exposed secrets are not merely dormant but operational. This creates immediate risk of credential abuse, unauthorized message sending, and account compromise if the code or logs are exposed.
When a URL is not whitelisted, the script silently sends the full checked URL and domain context to Feishu without explicit user disclosure or consent. This can leak sensitive URLs, internal endpoints, tokens embedded in query strings, or user activity metadata to an external service, making it a meaningful privacy and exfiltration risk.
The skill advertises and demonstrates file access, shell execution, subprocess use, and network interactions, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates a governance gap: a reviewer or runtime may not correctly constrain what the skill can do, increasing the chance of over-privileged execution or unnoticed sensitive actions.
L003 的描述全文使用中文来规定技能的触发与用途,文件其余内容也默认以中文进行交互与确认,但没有说明这是面向特定中文环境的合规需求,也没有提供用户可选择语言的机制。根据规则,未获用户选择即隐含强制特定语言/locale,属于自然语言层面的组织政策风险。
These API calls transmit audit contents to an external Feishu service, which can expose sensitive operational details outside the local trust boundary. In an audit/protection skill, logs may include high-risk actions, timestamps, and details, so undisclosed outbound transfer increases privacy and confidentiality risk.
This code file includes natural-language documentation in Chinese and later uses Chinese operation labels and status text, but does not provide any language selection or indicate that the skill is intentionally limited to a Chinese-speaking context. That creates a language/locale policy issue under the rule for forced language without user opt-in.
No suspicious patterns detected.