T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.en.md:177- Finding
Process-Global Session Key Fallback Can Cause Cross-Session Identity Confusion
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent one-time patch skill, but it changes Feishu authorization/session handling in ways that can confuse identities and expose session keys.
Install or run this only in a reviewed development workflow, after backing up the openclaw-lark plugin and confirming every diff. Avoid loading it as an always-on runtime skill. Do not use the unpinned npx reinstall path in production without pinning and verifying the package. The session-key fallback, persistent sessions.json lookup, and full session-key logging should be fixed or removed before deploying to a shared gateway.
SKILL.en.md:177Process-Global Session Key Fallback Can Cause Cross-Session Identity Confusion
SKILL.en.md:489Plugin Is Instructed to Read Persistent Agent Session State and May Log Complete Session Keys
SKILL.en.md:37Unpinned Package Is Downloaded and Executed Automatically Through npx
This skill is explicitly a self-/code-modification instruction set that directs an agent to create and modify many source files, alter hooks, and change runtime behavior. In a security context, broad agent-driven code modification is dangerous because a malicious or tampered skill can introduce backdoors, weaken identity boundaries, or persist unsafe logic across the codebase.
skills.entries. Use when porting or re-applying after merge conflicts.
---
# openclaw-lark: Agent Direct Tool Invocation Without Feishu Ticket (Full Patch Skill)
**Execution convention**: The paths below are relative to the **`openclaw-lark` extension root** (the directory containing `index.js` and `src/`). Before editing code, the implementing Agent **must complete "Before execution: explain to the user and wait for confirmation"** and receive **explicit user consent**, then modify code in **§B–§M** order and run the **acceptance commands** at the end, achieving **semantic equivalence** with the validated implementation below.
**Mandatory requirement**: Do not skip any section simply because "the current version structure is different / same-named snippets were not found"; you must find semantically equivalent locations in the current code and apply the same changes (see **§0.3 Strict Execution and Closed-Loop Acceptance Protocol**).
This section instructs how to load, enable, copy, and remove the patch skill within the agent/runtime skill system. That materially increases the skill's ability to modify its own operating environment and be invoked by other agents, expanding attack surface if the skill content is malicious or later replaced.
| **Use local AI tools only; do not load in OpenClaw** | Put `agent-feishu-direct-tools-patch` under **skills/rules/context** directories supported by your tool, or run by **@mention/pasting `SKILL.md` path** in chat; **do not** write it into `openclaw.json` `skills`. This way OpenClaw Gateway runtime **cannot see** this Skill at all. |
| **Temporarily load into OpenClaw** | If runtime **Gateway Agent** must read this doc: **temporarily** copy this directory into an existing folder under `skills.load.extraDirs`; **delete the copy after use** (or remove the extra directory added specifically for this patch), then **restart Gateway**. If it no longer appears in list, normal state is restored. |
| **Do not keep `enabled: true` long-term** | If config has `skills.entries.<name>`: do **not** keep this Skill permanently enabled; enable only when patching (if your OpenClaw version supports per-entry toggle), then switch back to **disabled** or remove the entry. |
| **Do not rely on "Agent auto-selects skill"** | Trigger explicitly with **one clear user sentence** (e.g., "apply openclaw-lark agent-feishu-direct-tools-patch"), avoiding mixing patch skill with daily always-on sets like `team-agent-onboarding`. |
| **Distribute via repo or archive** | Include the whole `agent-feishu-direct-tools-patch` directory in Git or package for reuse; whether runtime loads it is separate from whether files stay on disk — keeping files != must enable permanently in `skills.entries`. |
**Relation to §"Allow OpenClaw chat Agent to load this Skill"**: those items describe how to load when **short-term needed**; by default, still prefer **execute in AI-assisted dev tools + do not keep loaded in Gateway after use**, or **temporary load -> remove immediately after patch**.
Referenced artifact was not completely inspected
t-feishu-direct-tools-patch` 放在所用工具支持的 **skills / 规则 / 上下文** 目录,或在对话里 **@ / 粘贴 `SKILL.md` 路径** 执行;**不要**写入 `openclaw.json` 的 `skills`。这样 OpenClaw Gateway 运行时 **
Referenced artifact was not completely inspected
t-feishu-direct-tools-patch` 放在所用工具支持的 **skills / 规则 / 上下文** 目录,或在对话里 **@ / 粘贴 `SKILL.md` 路径** 执行;**不要**写入 `openclaw.json` 的 `skills`。这样 OpenClaw Gateway 运行时 **
This document explicitly instructs operators to load a patch skill into a runtime agent environment and even send the skill archive to a bot so it will automatically read and execute workflow instructions. That is a self-modifying/agent-directed code-change pattern: it expands the trust boundary, increases the chance of unintended code edits, and creates a path for prompt/instruction injection or unsafe autonomous modification of the OpenClaw/Lark integration.
- "Apply `agent-feishu-direct-tools-patch` to patch `openclaw-lark`."
3. You can also send the skill archive file directly to the OpenClaw bot in Feishu chat; the bot will automatically read and execute the workflow instructions.
4. After execution, remove the temporary skill copy or disable the entry.
5. Restart Gateway so this patch skill does not remain as daily-chat noise.
Note: exposing SKILL to runtime agents only provides instructions; it does **not** replace actual code edits and restart.
The skill instructs use of npx -y @larksuite/openclaw-lark install without pinning an exact package version. That causes execution of whatever version is current in the registry at runtime, which is a supply-chain risk: a malicious update, compromised publisher account, or breaking release could execute arbitrary code during install or overwrite the plugin with unexpected content.
This is a second occurrence of the same unpinned npx install instruction. Repeating the guidance in rollback/recovery steps increases the chance an operator will execute arbitrary newly-published code from the package registry during an incident, when scrutiny is already lower.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### When code editing can start
- **Required**: The user explicitly states agreement to execute this patch (e.g., "confirm execution", "start patching", "agree, modify according to Skill"; interpret equivalent expressions by locale).
- **Forbidden**: User only says "explain this Skill" / "what is this patch" without confirmation -> **explain only, do not edit files**.
- After confirmation, start from **§B**; throughout execution, still follow §0 completion reporting and restart notes in **"Patch and OpenClaw Runtime State"**.
---
This occurrence again directs a live reinstall from npm without version pinning. In the context of a patch skill that already performs broad code modifications, an unpinned recovery command compounds risk by making the final system state dependent on mutable external registry content.
The deployment/validation section repeats the same unpinned package execution. Because this is presented as an official fallback after patch failure, operators may treat it as safe and execute it immediately, exposing the environment to supply-chain compromise or unintended code changes.
The rollback section again recommends an unpinned npx package install. Recovery paths are especially sensitive because they are likely to be executed under time pressure, making the mutable-latest behavior of npx particularly dangerous.
If the manifest/front matter references the same unpinned package command, it embeds non-reproducible remote code execution guidance into the skill definition itself. That broadens exposure because automated tooling or users may trust manifest-level instructions as authoritative.
The skill instructs use of npx -y @larksuite/openclaw-lark install without pinning an exact package version. That allows the command to fetch whatever package version is current at execution time, creating supply-chain and reproducibility risk if a bad release, compromised package, or breaking update is published.
The skill body and operational instructions are presented in Chinese and direct the implementing agent to follow them as mandatory procedure, but the document does not offer the user any language or locale choice. This creates a language-policy concern because the skill effectively assumes a fixed language for execution guidance without documented opt-in or region-specific justification.
This is another unpinned npx install command in operational guidance. Because npx resolves the latest matching package by default, the exact code executed later may differ from what was originally reviewed, enabling accidental or malicious supply-chain drift.
The repeated recommendation to reinstall via unpinned npx increases the chance an operator will execute arbitrary newer package code not covered by this skill's review. In a patching workflow, that is especially risky because it combines code modification with later remote package execution.
This deployment/rollback instruction again relies on an unpinned package execution path. If the package changes or is compromised, recovery steps could introduce new code into a sensitive gateway/plugin environment.
The rollback section repeats an unpinned package install command, preserving the same supply-chain risk during incident response or recovery. Recovery paths are high leverage because users may run them quickly under pressure without additional scrutiny.
The document recommends reinstalling the plugin via npx -y @larksuite/openclaw-lark install without pinning an exact package version. That causes execution of whatever package version is current at install time, which weakens reproducibility and creates a supply-chain risk if a bad release or dependency compromise occurs.
The document instructs users to reinstall with npx -y @larksuite/openclaw-lark install without pinning a specific package version. That causes execution of whatever version is current on the registry at run time, which weakens supply-chain integrity and can unexpectedly introduce malicious or breaking changes during a recovery path. In this skill context, the risk is higher because the command is presented as a remediation step users may run under pressure after a failed patch.
The document says a robot can automatically read and execute a skill zip sent in chat, but it does not pair that workflow with strong warnings about arbitrary code/instruction execution, privilege scope, or trust boundaries. In practice, this encourages a dangerous pattern where untrusted artifacts delivered over messaging can trigger system modifications, which is especially risky for an agent skill whose purpose is to patch source code and alter runtime behavior.
The file is explicitly an English-only skill variant (SKILL.en.md), but the instructions do not offer a language choice or explain why English is required. Under the policy rule, forcing a specific language without user opt-in can be a locale-policy violation.
L004 表述为已提供英文版,但“如需使用,可自行重命名为 SKILL.md 替换当前中文版本”,显示当前默认生效的是中文版本。对语言/locale 政策而言,这种默认固定语言的方式未在使用点明确提供用户选择或 opt-in,可能导致语言偏好未被主动征询。
No suspicious patterns detected.