T09 · Insecure Skill Coding Practices
- Location
scripts/create_daily_todo.mjs:3- Finding
Hard-Coded Feishu Application Credentials
- Content
View full analysis
Vulnerability Details
File Location:
scripts/create_daily_todo.mjs:3-9
Vulnerability Type: Hard-coded application secret
Risk Level: HighVulnerable Code
javascript const APP_ID = 'cli_a92115f36af9dcd5'; const APP_SECRET = 'iRuP8Jj8LT5iJlFXTRpbiWJr2yRiBx84'; const USER_OPEN_ID = 'ou_3aed530e2f42a906b704bc474609d7ce'; const client = new Client({ appId: APP_ID, appSecret: APP_SECRET });Technical Analysis
The source code contains a plaintext Feishu application ID and application secret. The secret is included in a distributable Skill package and is therefore available to anyone who downloads the package or accesses its source repository.
Application secrets are bearer credentials used to authenticate the application to Feishu. The code passes the embedded credential directly to the Feishu SDK, allowing it to obtain access consistent with the application's configured tenant permissions. No environment-based configuration, secret manager, credential validation, or tenant isolation is used.
Although the audit could not verify whether the credential remains active, its format and direct use in executable code make it a credible exposed secret. Its privileges are bounded by the scopes granted to the corresponding Feishu application.
Attack Path
- An attacker downloads the published Skill or clones its repository.
- The attacker reads
scripts/create_daily_todo.mjs. - The attacker extracts the embedded application ID and secret.
- The attacker uses the credentials with the Feishu authentication API or SDK.
- If the credentials remain active, the attacker obtains an application access token.
- The attacker invokes any Feishu APIs permitted by the application's configured scopes.
Impact Assessment
Successful exploitation may allow an attacker to act as the embedded Feishu application. Depending on the actual tenant-side scopes, possible impact includes:
...[truncated 533 chars]
- Remediation
View remediation
Remediation Suggestions
-
Revoke and rotate the exposed Feishu application secret immediately.
-
Remove all credentials and tenant-specific identifiers from source code and repository history.
-
Load credentials from environment variables or a supported secret manager:
javascript const APP_ID = process.env.FEISHU_APP_ID; const APP_SECRET = process.env.FEISHU_APP_SECRET; if (!APP_ID || !APP_SECRET) { throw new Error('Feishu credentials are not configured'); } -
Require each installer to configure credentials for an application under their own control.
-
Grant that application only the minimum Feishu scopes required by enabled features.
-
Add automated secret scanning to the publication and continuous-integration process.
-
Review Feishu access logs for use of the exposed credential and invalidate active tokens where supported.
-
