Back to skill

Security audit

Super Lobster

Security checks for vulnerabilities and agentic risk

Overview

This looks like a private Feishu automation skill published with embedded credentials and fixed sharing behavior, so it needs human review before installation.

Do not install this as a general public skill without review. The publisher should rotate the exposed Feishu secret, remove hard-coded credentials and recipient IDs, require installer-owned configuration, remove unused message permission, and add explicit confirmation for document sharing and scheduled automation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/create_daily_todo.mjs:3
Finding

Hard-Coded Feishu Application Credentials

Content
View full analysis

Vulnerability Details

File Location: scripts/create_daily_todo.mjs:3-9
Vulnerability Type: Hard-coded application secret
Risk Level: High

Vulnerable Code

javascript
const APP_ID = 'cli_a92115f36af9dcd5';
const APP_SECRET = 'iRuP8Jj8LT5iJlFXTRpbiWJr2yRiBx84';
const USER_OPEN_ID = 'ou_3aed530e2f42a906b704bc474609d7ce';

const client = new Client({
  appId: APP_ID,
  appSecret: APP_SECRET
});

Technical Analysis

The source code contains a plaintext Feishu application ID and application secret. The secret is included in a distributable Skill package and is therefore available to anyone who downloads the package or accesses its source repository.

Application secrets are bearer credentials used to authenticate the application to Feishu. The code passes the embedded credential directly to the Feishu SDK, allowing it to obtain access consistent with the application's configured tenant permissions. No environment-based configuration, secret manager, credential validation, or tenant isolation is used.

Although the audit could not verify whether the credential remains active, its format and direct use in executable code make it a credible exposed secret. Its privileges are bounded by the scopes granted to the corresponding Feishu application.

Attack Path

  1. An attacker downloads the published Skill or clones its repository.
  2. The attacker reads scripts/create_daily_todo.mjs.
  3. The attacker extracts the embedded application ID and secret.
  4. The attacker uses the credentials with the Feishu authentication API or SDK.
  5. If the credentials remain active, the attacker obtains an application access token.
  6. The attacker invokes any Feishu APIs permitted by the application's configured scopes.

Impact Assessment

Successful exploitation may allow an attacker to act as the embedded Feishu application. Depending on the actual tenant-side scopes, possible impact includes:

...[truncated 533 chars]

Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate the exposed Feishu application secret immediately.

  2. Remove all credentials and tenant-specific identifiers from source code and repository history.

  3. Load credentials from environment variables or a supported secret manager:

    javascript
    const APP_ID = process.env.FEISHU_APP_ID;
    const APP_SECRET = process.env.FEISHU_APP_SECRET;
    
    if (!APP_ID || !APP_SECRET) {
      throw new Error('Feishu credentials are not configured');
    }
    
  4. Require each installer to configure credentials for an application under their own control.

  5. Grant that application only the minimum Feishu scopes required by enabled features.

  6. Add automated secret scanning to the publication and continuous-integration process.

  7. Review Feishu access logs for use of the exposed credential and invalidate active tokens where supported.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/create_daily_todo.mjs:224
Finding

Documents Are Shared with a Hard-Coded External Identity

Content
View full analysis

Vulnerability Details

File Location: scripts/create_daily_todo.mjs:5 and scripts/create_daily_todo.mjs:224-236
Related Sensitive Content: scripts/create_daily_todo.mjs:26-161
Vulnerability Type: Fixed recipient and unintended information disclosure
Risk Level: High

Vulnerable Code

javascript
const USER_OPEN_ID = 'ou_3aed530e2f42a906b704bc474609d7ce';
javascript
const permRes = await client.drive.permissionMember.create({
  path: { token: docToken },
  params: {
    type: 'docx',
    need_notification: true
  },
  data: {
    member_type: 'openid',
    member_id: USER_OPEN_ID,
    perm: 'edit'
  }
});

The document body is also statically populated with internal-looking business tasks, responsible individuals, project deadlines, commercial plans, and project values before the permission is granted.

Technical Analysis

Every execution grants edit access to the same hard-coded Feishu Open ID. The recipient is not supplied by the installer or invoking user, is not validated against the current tenant, and is not shown for confirmation before the permission-changing API request is made.

The API request also sets need_notification: true, which may actively notify the fixed recipient that a new document has been shared. Because the generated document includes detailed business meeting information, execution can transmit that content to an identity unrelated to the person installing the public Skill.

The use of a hard-coded recipient defeats tenant isolation and safe deployment assumptions. Even if the recipient was appropriate for the original author, it is not safe as a default in a redistributable package.

Attack Path

  1. A user installs the published Skill and invokes the documented create-todo command.
  2. The script authenticates using the embedded Feishu application credentials.
  3. It creates a document containing the hard-coded meeting a ...[truncated 1205 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the hard-coded Open ID and all tenant-specific identifiers.
  2. Require the recipient to be explicitly configured at runtime or through an installation-specific configuration file.
  3. Validate that the recipient belongs to the expected tenant and display the resolved recipient identity before sharing.
  4. Obtain explicit user confirmation before granting access or sending a notification.
  5. Default to the least privilege, such as read-only access, unless edit access is specifically required.
  6. Provide an option to create the document without sharing it.
  7. Replace the embedded business records with a neutral template or obtain task data from a user-authorized source at runtime.
  8. Add rollback logic that revokes permissions if later processing fails.
  9. Review previously generated documents and revoke access granted to the fixed Open ID where it was not intended.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
_meta.json:23
Finding

Unnecessary Feishu Messaging Permission Is Declared

Content
View full analysis

Vulnerability Details

File Location: _meta.json:23-27 and clawhub.json:29-33
Vulnerability Type: Excessive permission declaration
Risk Level: Medium

Vulnerable Code

_meta.json:

json
"permissions": [
  "feishu:docx:write",
  "feishu:permission:manage",
  "feishu:message:send"
]

clawhub.json:

json
"permissions": [
  "feishu:docx:write",
  "feishu:permission:manage",
  "feishu:message:send"
]

Technical Analysis

The package declares feishu:message:send, but the only supplied executable script does not send Feishu messages. It creates a document, inserts document blocks, changes document permissions, and prints a URL to standard output.

Requesting a capability that is not required by the implemented functionality violates the principle of least privilege. The documentation advertises message delivery, but the corresponding implementation is absent from the audited package. A documented future feature is not sufficient justification for granting the current release that capability.

The manifest declaration alone does not prove that tenant-side messaging access has been granted. However, if the platform or installer maps these declared permissions to actual application scopes, the unnecessary permission increases the impact of credential compromise or future code changes.

Attack Path

  1. A user installs the Skill and approves its declared permissions.
  2. The platform or Feishu administrator grants the application message-sending capability.
  3. An attacker obtains the embedded application credential, compromises the runtime, or introduces code through a later update.
  4. The attacker uses the unnecessary messaging scope to send messages as the application.
  5. Recipients may trust those messages because they originate from an approved tenant application.

Impact Assessment

If the declared scope is granted tenant-side, compromise could permit ...[truncated 523 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove feishu:message:send from both manifests for the current release.
  2. Reconcile declared capabilities with the behavior of the files actually included in the package.
  3. If messaging is later implemented, make it an optional feature with a separate permission request and explicit user consent.
  4. Use separate Feishu applications or credentials for document management and messaging where practical.
  5. Audit the tenant-side application configuration and revoke any messaging scope not currently required.
  6. Add a release check that rejects permissions not mapped to reviewed, included functionality.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document title and all usage instructions are written in Chinese, which effectively forces a specific language for users without any opt-in or alternative. The policy allows locale constraints when they are explicitly justified or optional, but that is not stated here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README advertises capabilities that can access and transform potentially sensitive work data, create documents, change permissions, and run scheduled tasks, but it provides no warning, consent expectations, or scope limitations. In an enterprise assistant context, this can lead users to trigger privacy-impacting or system-impacting actions without understanding what data will be read, where outputs will be written, or how permissions and automation will behave.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly advertises automatic reading of meeting notes, creation of Feishu documents, permission changes, and pushing content, but does not warn users about the privacy and sharing implications of those actions. In a productivity skill handling potentially sensitive work documents, silent automation of read/share/write operations can cause unintended disclosure or modification of internal data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes cron- and heartbeat-triggered execution that can automatically read meeting notes, update to-do documents, and push urgent items without any per-run confirmation or safety notice. In this context, unattended execution increases the chance of unauthorized data processing, accidental resharing, or repeated document modifications when triggered in the background.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The metadata description is very broad and covers multiple powerful actions such as reading meeting notes, classifying tasks, creating Feishu documents, managing permissions, and sending messages. In an agent ecosystem, an overly broad description can cause the skill to be invoked outside its intended scope, which increases the chance of unnecessary access to sensitive workplace content and misuse of its granted permissions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
71% confidence
Finding

The display name and description prominently mix or use Chinese language content, and the description frames the skill as a private assistant for a specific individual without indicating language choice or user opt-in. This may violate language/locale policy if the skill implicitly constrains interaction to a specific language without offering alternatives or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This manifest file describes the skill as a private AI assistant integrating document management, meeting-note organization, and daily todo pushing, but it does not specify when or how the skill should be invoked. In a manifest, such broad assistant-style wording can create ambiguous activation boundaries and increase the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script hard-codes a Feishu app ID, app secret, and a specific user OpenID directly in source code. Embedded credentials are highly sensitive because anyone with repository or package access can reuse them to authenticate to Feishu APIs, create or modify documents, and potentially access or grant permissions to organizational data without additional approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically grants edit access on the newly created document to a fixed user without confirming that the operator intended to share the document or that this recipient is authorized. In an assistant skill that processes meeting notes and task data, silent permission changes can leak sensitive business information and enable unauthorized modification of records.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The description presents the assistant in Chinese and frames it as a private assistant for a specific user context, with no indication that users may choose another language or locale. Under the policy provided, language or locale constraints should either be optional or explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The document title, status labels, and task content are all fixed in Chinese, which imposes a specific language on generated output. There is no indication that the user can choose another language or that the locale restriction is documented as intentional and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.