Back to skill

Security audit

Feishu File Sender

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Feishu file-staging helper, but it can persist very broad OpenClaw filesystem permissions and includes a cleanup command that can delete arbitrary writable files.

Install only if you are comfortable manually changing OpenClaw filesystem permissions. Avoid the medium and loose presets, especially /**, and do not run clean.js with any path unless you have verified it points to a temporary file created by this skill.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/perm-config.js:85
Finding

Excessive Filesystem Permissions Violate Least Privilege

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/clean.js:23
Finding

Arbitrary File Deletion Through Unvalidated Cleanup Path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a temporary-directory workaround, yet the instructions explicitly tell users to run scripts that modify persistent OpenClaw configuration and broaden filesystem allowlists up to '/**'. This is dangerous because it turns a narrowly scoped helper into a permission-escalation/configuration utility with system-wide file-read implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill presents itself as a temporary-directory workaround, yet the instructions explicitly tell users to run scripts that modify persistent OpenClaw configuration and broaden filesystem allowlists up to '/**'. This is dangerous because it turns a narrowly scoped helper into a permission-escalation/configuration utility with system-wide file-read implications.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
node scripts/perm-config.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
node scripts/perm-config.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
node scripts/perm-config.js

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
node scripts/perm-config.js

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
96% confidence
Finding

The lockfile pins axios to 1.13.6, and the supplied advisories indicate multiple known security issues including SSRF-related proxy bypass and prototype-pollution-assisted request/response compromise paths. In a skill whose purpose is sending files over HTTP to Feishu, a vulnerable HTTP client is especially relevant because it handles outbound network requests, headers, redirects, and potentially credentials or file-upload metadata.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
88% confidence
Finding

form-data 4.0.5 is reported vulnerable to CRLF injection via unescaped multipart field names/filenames. In a file-sending skill, multipart construction is core functionality, so if any filename or form field can be influenced by untrusted input, an attacker may be able to inject malformed parts or smuggle unintended headers/content in outbound requests.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency specification can resolve to axios 1.13.6, which is reported as having multiple known advisories, including SSRF-related and proxy/credential-handling issues. Because this skill is specifically for sending files through Feishu and likely performs outbound HTTP requests, a vulnerable HTTP client is especially relevant and could expose tokens, redirect traffic, or weaken network trust boundaries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The generated permission presets materially exceed the skill's stated purpose of solving a temporary-directory whitelist issue for Feishu file sending. Offering allowlists that span home directories, multiple drives, system paths, and even whole-system access creates an unnecessary expansion of the host agent's file access surface, enabling unrelated file read/write operations if the skill or another component abuses the granted permissions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The '宽松' preset explicitly grants '/**', effectively whole-system read/write access. For a file-sending helper whose described goal is only to work around a temporary-directory whitelist, this is unjustified and creates a severe over-permissioning path that could expose sensitive files or allow destructive writes anywhere on the system.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code persists broad filesystem allowlist entries directly into the user's OpenClaw configuration, changing host-wide security settings rather than just handling the skill's own runtime temp-file behavior. Because the modification is durable and affects a named skill entry, it can silently broaden future access and normalize over-privileged operation beyond the immediate task.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents scripts that inspect environment-dependent state and modify OpenClaw behavior, but it does not declare explicit tool scope or permissions metadata beyond path requirements. That weakens user visibility and policy enforcement, making it easier for a seemingly simple file-transfer helper to exercise broader capabilities than expected.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest and introductory description frame the skill as a temporary-directory workaround, but the documented behavior includes modifying OpenClaw configuration to expand allowed filesystem access. That mismatch obscures a security-sensitive action, increasing the chance users consent to a broader trust boundary change than they intended.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented permission-configuration capability expands OpenClaw file access well beyond temporary-file preparation, including broad path ranges and an option for whole-system access. In context, this is more dangerous because the skill's stated purpose only needs controlled staging in a temp directory, so the extra access is unnecessary and materially increases exposure of sensitive files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow copies user files into '/tmp' and later deletes them, but the docs do not clearly explain the confidentiality and lifecycle risks of temporary storage. On multi-user or poorly configured systems, temp files may be exposed, left behind after failures, or unintentionally deleted incorrectly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs users to write to '~/.openclaw/openclaw.json' and choose permission levels, including very broad access, without a clear warning that this changes system-wide agent file access. This can lead to overpermissioned configurations that persist beyond the skill and affect unrelated workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s header comments and CLI output strings are written only in Chinese, with no indication that the skill is region-specific or that users can select another language. This creates a natural-language locale policy issue because the skill implicitly forces a specific language rather than offering choice or documenting a justified constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script prints the temporary directory path, per-file absolute paths, and associated URLs directly to stdout in structured JSON. In the context of a file-sending helper designed to work around a whitelist restriction, this metadata may expose sensitive local filesystem locations and shareable access URLs to logs, calling processes, or other users who can read command output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Comments and, more importantly, runtime console messages and usage text are presented only in Chinese throughout the script. This imposes a specific language on all users without any visible locale selection or documented regional constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Even the supposedly safer presets include expansive directories such as all of /home, /Users, /var, /srv, /opt, multiple Windows drives, and private temp areas. This exceeds what is needed for a temporary-directory workaround and increases the blast radius for accidental exposure or intentional misuse of files unrelated to Feishu transfer.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script writes security-relevant configuration changes to the host OpenClaw config immediately when invoked with an option, without an interactive confirmation step or explicit risk acknowledgment. This makes it easier for users to apply dangerous permission changes unintentionally, especially because the presets themselves are overbroad.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s header comments, usage text, and later console messages are entirely in Chinese, which imposes a specific language on users. The policy only allows this when the skill offers language choice or clearly documents a justified locale restriction, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Comments and user-facing error/message strings in this file are written in Chinese, including the thrown error and returned status messages, with no indication that the skill supports alternative languages or that the locale restriction is intentional. This can violate the language/locale policy when a skill effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code exposes deleteTempFile and cleanTempDir, which permanently delete files via fs.unlinkSync, but there is no confirmation prompt, user-facing log/print, or warning comment/docstring indicating that data will be removed. For code-file review under SQP-2, irreversible file deletions should include some form of disclosure unless clearly covered elsewhere, which is not visible in this file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.