Back to skill

Security audit

Create Colleague

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent goal, but it needs Review because it can collect and store private workplace communications, credentials, browser-session data, and persistent persona instructions with weak safeguards.

Install only if you have explicit authorization from your organization and the people whose communications may be processed. Avoid private-chat collection, browser scraping, raw screenshots, and voice/identity cloning use cases unless there is documented consent. Use narrowly scoped read-only credentials, do not use the example.com OAuth redirect, pin external tools before use, and review every generated skill before enabling it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:938
Finding

Generated Skills Attempt to Override the Agent Instruction Hierarchy

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
tools/feishu_mcp_client.py:94
Finding

Runtime Execution of an Unpinned npm Package with Feishu Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
tools/feishu_mcp_client.py:45
Finding

Plaintext Credential Files Are Written Without Enforced Restrictive Permissions

Content
View full analysis
None: CONFIG_PATH.parent.mkdir(parents=True, exist_ok=True) CONFIG_PATH.write_text(json.dumps(config, indent=2)) ``` The configuration object can contain the following secrets: ```python config = { "app_id": app_id, "app_secret": app_secret, "mode": "app" if mode == "1" else "user", } if mode == "2": user_token = input("User Access Token (u-xxx): ").strip() config["user_token"] = user_token ``` Equivalent plaintext writes are used for Feishu auto-collector credentials, DingTalk App Secrets, and Slack bot tokens. ### Technical Analysis Sensitive credentials are serialized directly into JSON files under `~/.colleague-skill/`. The code does not set the containing directory to mode `0700`, create files with mode `0600`, check existing permissions, or use an operating-system credential manager. Actual permissions depend on the user's umask and pre-existing directory state. On systems with permissive settings, other local users or processes may be able to read these files. The implementation also conflicts with `CONTRIBUTING.md`, which recommends permission mode `0600` for credential files. ### Attack Path 1. A user runs a collector's setup procedure. 2. The Skill writes an App Secret, bot token, refresh token, or user access token into a plaintext JSON file. 3. The file is created with permissions derived from the current umask or inherits an insecure pre-existing state. 4. Another local user, compromised process, backup utility, or synchronization tool reads the file. 5. The attacker reuse ...[truncated 440 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:637
Finding

OAuth Authorization Code Is Redirected to an Unrelated Plaintext HTTP Endpoint

Content
View full analysis
The redirect_uri must be added in the app's "Security Settings → Redirect URLs" 2. User opens URL, logs in, authorizes 3. Page redirects to `http://www.example.com?code=xxx`, user copies the code ``` ### Technical Analysis The documented flow instructs users to register and use `http://www.example.com` as an OAuth redirect URI. This endpoint is unrelated to the project and does not use transport encryption. OAuth authorization codes are bearer-like, short-lived secrets used to obtain access tokens. Sending a code to an unrelated host exposes it to that host's operator. Using HTTP additionally allows network observers or active man-in-the-middle attackers to intercept or modify the redirect. The flow also does not document PKCE or a verified state parameter. These omissions further reduce protection against authorization-code interception and request forgery. ### Attack Path 1. A user adds `http://www.example.com` to the Feishu application's redirect allowlist. 2. The user opens the generated authorization URL and grants the requested message and chat scopes. 3. Feishu redirects the browser to the unrelated HTTP endpoint with the authorization code in the query string. 4. The endpoint operator, a network observer, proxy, browser-history collector, or log processor obtains the code. 5. The attacker attempts to exchange the code for a user access token before the legitimate user does. ### Impact Assessment If the code is successfully exchanged, the attacker may obtain a Feishu user access token with the approved scopes. The documented scopes include reading or sending messages and ac ...[truncated 177 chars]
Remediation
View remediation
/callback`, as permitted for native applications. 2. Alternatively, use a project-controlled HTTPS callback with strict transport security. 3. Implement PKCE using a high-entropy verifier and `S256` challenge. 4. Generate and verify a cryptographically random OAuth `state` value. 5. Bind a local callback server only to the loopback interface and stop it immediately after receiving the response. 6. Never ask users to copy authorization codes from unrelated third-party pages. 7. Minimize requested scopes and clearly display them before authorization. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:679
Finding

Feishu User Access Token Is Passed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (227)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The roadmap proposes cloning a person's voice from meeting recordings and voice messages without any mention of informed consent, biometric data handling, impersonation safeguards, or abuse prevention. Voiceprints are sensitive biometric identifiers, and in this skill's context the feature would enable highly convincing impersonation of real individuals, increasing risks of fraud, social engineering, harassment, and severe privacy violations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description presents a broader end-to-end skill: collect Feishu/DingTalk data, generate a colleague-derived AI Skill including Work + Persona, and support continuous evolution. The supplied code only covers one subset of that pipeline: DingTalk data collection. It does not generate any AI Skill, persona, or evolution behavior. It also does not include Feishu support in this chunk. Additionally, the declared permissions are empty, but the code clearly accesses sensitive enterprise resources (contacts, docs, tables, and chat records via browser automation) and writes them to disk. That is a material mismatch between the declared description/permissions and the actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on building an AI representation of a colleague through automatic Feishu/DingTalk data collection and persona/skill generation. The supplied code does none of that directly. It only processes email data from local files (.eml, .mbox, .txt), filters by sender, extracts text, performs simple categorization, and outputs formatted content for potential downstream use. While this could be a supporting component in a broader colleague-distillation pipeline, the actual code chunk's primary purpose and accessed resource type (email files) differ materially from the declared Feishu/DingTalk auto-collection and persona-generation functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents a broader end-to-end skill that both collects enterprise data from Feishu and DingTalk and transforms it into a colleague-derived AI Skill with persona/work synthesis and ongoing evolution. The supplied code only implements a Feishu data collector. It performs user lookup, group/private message retrieval, document/wiki search and content fetching, optional bitable reading, token exchange/setup, and local file export. There is no DingTalk code, no generation of persona/work skill artifacts, and no continuous evolution mechanism. Additionally, the declared permissions are empty, while the code clearly requires and uses substantial access to messaging, contacts, docs, wiki, drive, and bitable resources. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises an end-to-end colleague-distillation capability: collecting Feishu/DingTalk data, producing a Work Skill and Persona, and continuously evolving that representation. The supplied code only implements one narrow component: browser-based extraction of Feishu content using an existing Chrome login state. That means its actual behavior is materially different from the declared purpose in two ways. First, it includes a sensitive undeclared capability: accessing authenticated Feishu resources and message history by reusing the user's browser profile. Second, it does not implement the core claimed functionality of generating a colleague persona/skill or any continuous evolution pipeline. It also does not support DingTalk despite that being explicitly declared. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code chunk is narrowly focused on retrieving Feishu content through an MCP server: it configures Feishu credentials, calls MCP tools to read docs/wiki/messages, filters chat messages, lists wiki documents, and saves output. It does not implement any logic for 'distilling a colleague,' generating an AI Skill, producing a Work/Persona model, or supporting continuous evolution. It also does not include any DingTalk integration. While Feishu data collection is loosely aligned with part of the description, the primary declared purpose is a higher-level colleague-to-skill generation system, which this code does not perform. Additionally, the declared permissions are empty, but the code clearly accesses enterprise documents and messages using app/user tokens.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents a broader end-to-end skill for automatically collecting workplace chat data from Feishu/DingTalk and transforming it into an evolving AI representation of a colleague. The supplied code only implements a narrow preprocessing utility: it reads an input file, extracts messages for a named sender, classifies them into long/decision/daily buckets, and writes formatted output. This is related to the overall theme but materially narrower and missing the key advertised capabilities. No undeclared sensitive behavior is evident, but the description significantly overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description promises an end-to-end system that automatically collects colleague data from Feishu/DingTalk and distills it into an evolving AI Skill with Work and Persona generation. The supplied code does not access Feishu, DingTalk, network resources, messages, or external APIs at all. Instead, it is a filesystem utility that takes already-prepared meta/work/persona content and writes or updates local skill files, including SKILL.md, meta.json, and version backups. While versioning and corrections loosely relate to 'continuous evolution,' the core claimed capabilities—automatic collection and generation—are absent. Therefore the code's actual primary purpose materially differs from the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description says the skill auto-collects Feishu/DingTalk data and generates a Work Skill + Persona for continuous evolution. The supplied code chunk does something materially different: it is specifically a Slack data collector using Slack APIs and bot scopes, with no Feishu or DingTalk integration at all. Its primary implemented function is message collection from shared Slack channels and outputting text/JSON files for downstream analysis. While downstream analysis is hinted at in comments, this code itself does not generate the promised Work Skill or Persona. Because the accessed resource (Slack) differs from the declared platforms (Feishu/DingTalk), and the implemented capability is narrower and materially different from the declared purpose, this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a system for ingesting colleague data from Feishu/DingTalk and generating/evolving AI Skill representations. The supplied code does not perform data collection, API access, content generation, or evolution logic. Instead, it manages local filesystem versions of existing skill files (SKILL.md, work.md, persona.md) via list/backup/rollback/cleanup operations. This is a materially different primary purpose and introduces an undeclared capability: version archive management and rollback. Therefore the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The description markets the skill as a colleague-distillation helper but does not clearly disclose that it may collect private messages, documents, spreadsheets, emails, and profile data into a persistent knowledge base. That omission undermines informed consent for highly sensitive processing.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow normalizes aggregating messages, documents, spreadsheets, emails, and pasted text into a persistent knowledge base for later synthesis into a persona and skill. Centralizing this breadth of sensitive data creates a durable surveillance dataset that can expose personal, confidential, and proprietary information if misused or leaked.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This section directs collection of full private Feishu conversations but does not present a conspicuous warning or consent gate immediately beforehand. Collecting complete two-party message history for persona synthesis is highly intrusive and requires explicit notice and authorization.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instructions direct ingestion of full private chat histories and contact-visible identity data to build a persona profile of another person. This is a classic over-collection pattern: it gathers sensitive communications and personal identifiers far beyond what is necessary for many legitimate use cases, with significant privacy, insider-risk, and misuse potential.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to send a real message to a target user solely to discover private chat metadata, causing an externally visible action against a third party without that person's consent. This can expose the operator, leak that monitoring is occurring, and facilitate unauthorized collection of private communications.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow explicitly endorses browser-based scraping of DingTalk message history when the platform API does not support such access. Bypassing platform limits through scraping can violate access controls, terms of service, and privacy expectations while collecting highly sensitive employee communications.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 474)May include surrounding context.

md
6. 重新生成 `SKILL.md`(合并最新 work.md + persona.md)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 487)May include surrounding context.

md
6. 重新生成 `SKILL.md`(合并最新 work.md + persona.md)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 974)May include surrounding context.

md
6. 重新生成 `SKILL.md`(合并最新 work.md + persona.md)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 987)May include surrounding context.

md
6. 重新生成 `SKILL.md`(合并最新 work.md + persona.md)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Using rm -rf colleagues/{slug} with a user-influenced parameter creates a path-manipulation and destructive deletion risk. If slug is malformed or insufficiently validated, an attacker could cause deletion outside the intended directory or remove unexpected content.

Content

Scanner excerpt · SKILL.md (reported line 506)May include surrounding context.

/delete-colleague {slug}: 确认后执行:

bash
rm -rf colleagues/{slug}

Self-Modification

High
Category
Rogue Agent
Confidence
95% confidence
Finding

The skill is explicitly empowered to write and edit skill files, including updating stored behavior and persona content over time. Self-modifying or self-extending behavior increases persistence and can entrench unsafe instructions or poisoned data without robust review gates.

Content

Scanner excerpt · SKILL.md (reported line 549)May include surrounding context.

md
| Feishu docs (MCP App Token) | `Bash` → `python3 ${CLAUDE_SKILL_DIR}/tools/feishu_mcp_client.py` |
| DingTalk auto-collect | `Bash` → `python3 ${CLAUDE_SKILL_DIR}/tools/dingtalk_auto_collector.py` |
| Parse email .eml/.mbox | `Bash` → `python3 ${CLAUDE_SKILL_DIR}/tools/email_parser.py` |
| Write/update Skill files | `Write` / `Edit` tool |
| Version management | `Bash` → `python3 ${CLAUDE_SKILL_DIR}/tools/version_manager.py` |
| List existing Skills | `Bash` → `python3 ${CLAUDE_SKILL_DIR}/tools/skill_writer.py --action list` |

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This is the English duplicate of the instruction to send a message to the target user in order to obtain private chat metadata. It creates the same risk of unauthorized contact, privacy intrusion, and covert collection of private conversation context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This English section explicitly approves browser scraping of DingTalk message history despite lack of official API support. That instruction normalizes circumvention of platform boundaries to harvest sensitive communications and materially raises privacy and compliance risk.

Content

No source excerpt is available for this finding.

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Prompting users to upload chat screenshots as a fallback increases the chance of exposing unrelated conversation context, third-party personal data, and confidential information that cannot be easily filtered. Images are especially hard to sanitize consistently before ingestion and storage.

Content

Scanner excerpt · SKILL.md (reported line 742)May include surrounding context.

md
- `knowledge/{slug}/bitables.txt`
- `knowledge/{slug}/messages.txt`

If message collection fails, prompt user to upload chat screenshots.

---

Static analysis

No suspicious patterns detected.