Back to skill

Security audit

给钉钉的联系人或者群发送信息

Security checks for vulnerabilities and agentic risk

Overview

This DingTalk automation skill matches its stated purpose, but it can send real messages through desktop automation and exposes an unsafe caller-controlled queue file path.

Review this skill carefully before installing. It is intended to send DingTalk messages, so only use it in a controlled desktop session where you can monitor the active window. Avoid using the batch queue_file option unless the code is changed to restrict it to a safe app-owned directory, and prefer a version that confirms the recipient and message before pressing Enter.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
server.py:289
Finding

Caller-Controlled Queue Path Allows Arbitrary File Creation, Overwrite, and Deletion

Content
View full analysis
= len(queue_data.get("contacts", [])): queue_data = { "contacts": contacts, "message": message, "current_index": 0 } ``` ### Technical Analysis The public `dingding_send_batch` tool accepts a caller-supplied `queue_file` path and passes it directly to file-reading, writing, and deletion operations. The code performs no canonicalization, directory confinement, ownership validation, symbolic-link protection, or regular-file validation. Consequently, an MCP ca ...[truncated 1850 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
server.py:110
Finding

Blind Global GUI Automation Can Transmit Messages to an Unintended Application or Recipient

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Third-Party Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (15)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · test_dingding.py (reported line 20)May include surrounding context.

python
def test_send_current(message):
    print(f"\n=== Test: Send Message to Current ===")
    print(f"Message: {message}")
    
    success = send_message_to_current(message)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · test_dingding.py (reported line 34)May include surrounding context.

python
def test_send_current(message):
    print(f"\n=== Test: Send Message to Current ===")
    print(f"Message: {message}")
    
    success = send_message_to_current(message)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documentation describes capabilities that rely on local state files such as send_queue.json, and the static analyzer detected file read/write behavior, but the manifest does not declare any tool scope or permissions boundaries. This creates an authorization gap where a skill with filesystem interaction may operate without explicit user-reviewable constraints, increasing the risk of unintended local file access or tampering.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and usage instructions are entirely in Chinese and specify input formatting in that locale, with no indication that another language or locale is supported. This can violate language/locale policy when a skill forces a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Comments, user-facing strings, tool descriptions, and the window-title match for "钉钉" assume a Chinese locale and do not provide any opt-in or alternative language handling. This can violate language/locale policy when a skill forces one locale-specific behavior without user choice or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code performs irreversible GUI automation to send outbound DingTalk messages immediately, using simulated keystrokes and clicks with no confirmation, preview, or destination verification. If triggered accidentally or with crafted inputs, it can message the wrong contact or send unintended content, especially because it relies on focus and hard-coded coordinates.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes a skill for sending DingTalk messages to a specified contact, implying recipient targeting is part of the skill’s scope. However, send_message_to_current sends whatever text is provided to whichever chat input is currently focused, bypassing contact selection entirely and expanding behavior beyond the stated description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The batch API accepts an arbitrary queue_file path and writes JSON data there, allowing the caller to cause file creation or overwrite outside the skill directory. Because the file contents include recipient names, message text, and state, this can leak sensitive data and can clobber user files if a dangerous path is supplied.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The batch feature persists message content and recipient lists to disk and supports repeated sends across multiple invocations without presenting a clear warning or confirmation for each outbound action. This increases the chance of silent bulk messaging and leaves sensitive communication metadata stored locally longer than necessary.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
80% confidence
Finding

The trigger dt is very short and can be invoked accidentally or collide with unrelated user input. In this skill's context, accidental invocation is more concerning than usual because the skill performs GUI keyboard automation to send messages, so an unintended match could cause messages to be sent to real contacts.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency pyautogui is unpinned, which makes builds non-reproducible and can cause the skill to install an unexpected newer or compromised release. In a UI automation skill that simulates keyboard input on Windows, dependency drift increases supply-chain risk because a malicious or vulnerable update could gain access to desktop automation capabilities.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
pyautogui
pygetwindow
pillow
pyperclip

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency pygetwindow is unpinned, so the installed version may vary over time and across environments. Because this skill interacts with desktop windows and targets specific applications, an unexpected dependency version could introduce vulnerable behavior or malicious code into a privileged automation workflow.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
pyautogui
pygetwindow
pillow
pyperclip

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

Pillow is unpinned, and the manifest gives no assurance which release will be installed. This is more concerning than a generic unpinned package because Pillow has a history of security advisories; in combination with version drift, the skill could resolve to a vulnerable release with image parsing or code execution issues.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
pyautogui
pygetwindow
pillow
pyperclip

Unverifiable Dependency: pillow has 16 known advisory(ies) (CVE-2016-2533 (Pillow buffer overflow in ImagingPcdDecode); CVE-2023-50447 (Arbitrary Code Execution in Pillow); CVE-2021-27922 (Pillow Uncontrolled Resource Consumption) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The manifest includes Pillow without a version pin even though the package has multiple known security advisories. That means it is impossible to verify from this file whether the installed release is patched, and the skill may inadvertently deploy a vulnerable version; this is especially relevant if any image handling occurs in the automation environment.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency pyperclip is unpinned, allowing uncontrolled version selection at install time. Since this skill automates message sending and likely uses the clipboard as part of that flow, a malicious or vulnerable dependency update could affect sensitive clipboard contents or the integrity of sent messages.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
pyautogui
pygetwindow
pillow
pyperclip

Static analysis

No suspicious patterns detected.