Back to skill

Security audit

Feishu(Lark)Multi-Agent Tool-Use Patch

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent one-time patch skill, but it changes Feishu authorization/session handling in ways that can confuse identities and expose session keys.

Install or run this only in a reviewed development workflow, after backing up the openclaw-lark plugin and confirming every diff. Avoid loading it as an always-on runtime skill. Do not use the unpinned npx reinstall path in production without pinning and verifying the package. The session-key fallback, persistent sessions.json lookup, and full session-key logging should be fixed or removed before deploying to a shared gateway.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.en.md:177
Finding

Process-Global Session Key Fallback Can Cause Cross-Session Identity Confusion

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.en.md:489
Finding

Plugin Is Instructed to Read Persistent Agent Session State and May Log Complete Session Keys

Content
View full analysis
result (including `undefined`). 3. Inside `api.register(...)`, in `before_tool_call` / `after_tool_call`: - `before_tool_call`: **must support dual args** (`arg1, arg2`), use `arg1?.toolName ? arg1 : arg2` for `event`, and `arg1?.sessionKey ? arg1 : arg2` for `ctx`. Resolve from `ctx.sessionKey` or `event.sessionKey`; if missing, use `resolveSessionKeyFromStore(ctx.agentId, ctx.sessionId)`. Resolve `toolCallId` from `event` or `ctx`. If `resolvedSk` exists: `bindToolCallContext({ sessionKey: resolvedSk, agentId: ctx?.agentId })`; if `toolCallId` exists then `registerSessionKeyForToolCall(toolCallId, resolvedSk)`. Optional: when `event.toolName === "feishu_calendar_event"`, log one `log.info` including `agentId`, `sessionId`, `toolCallId`, `resolvedSkPresent`, `resolvedFromStore`, `resolvedSk`. ``` ### Technical Analysis The patch expands the Feishu plugin's authority beyond invocation-local context by directing it to read persistent OpenClaw agent session records from `sessions.json`. The retrieved `hit.key` is treated as a trusted session identity and retained in an in-memory map. This cros ...[truncated 2701 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.en.md:37
Finding

Unpinned Package Is Downloaded and Executed Automatically Through npx

Content
View full analysis
Remediation
View remediation
install ``` 2. Verify the package tarball integrity against a trusted, separately distributed SHA-256 or npm integrity value before execution. 3. Use an allowlisted registry over TLS and verify npm registry configuration before retrieval. 4. Prefer downloading the package without executing it, inspecting its contents and lifecycle scripts, and then running the verified local artifact. 5. Use a lockfile or an internal artifact repository that preserves reviewed versions. 6. Avoid suppressing confirmation with `-y` for security-sensitive recovery operations. 7. Run installation with a minimally privileged operating-system account. 8. Back up the plugin directory and configuration before installation. 9. Disable unnecessary lifecycle scripts where compatible with the official installation procedure. 10. Record the exact package version and integrity value in deployment and rollback logs. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (23)

Self-Modification

High
Category
Rogue Agent
Confidence
95% confidence
Finding

This skill is explicitly a self-/code-modification instruction set that directs an agent to create and modify many source files, alter hooks, and change runtime behavior. In a security context, broad agent-driven code modification is dangerous because a malicious or tampered skill can introduce backdoors, weaken identity boundaries, or persist unsafe logic across the codebase.

Content

Scanner excerpt · SKILL.en.md (reported line 14)May include surrounding context.

md
skills.entries. Use when porting or re-applying after merge conflicts.
---

# openclaw-lark: Agent Direct Tool Invocation Without Feishu Ticket (Full Patch Skill)

**Execution convention**: The paths below are relative to the **`openclaw-lark` extension root** (the directory containing `index.js` and `src/`). Before editing code, the implementing Agent **must complete "Before execution: explain to the user and wait for confirmation"** and receive **explicit user consent**, then modify code in **§B–§M** order and run the **acceptance commands** at the end, achieving **semantic equivalence** with the validated implementation below.  
**Mandatory requirement**: Do not skip any section simply because "the current version structure is different / same-named snippets were not found"; you must find semantically equivalent locations in the current code and apply the same changes (see **§0.3 Strict Execution and Closed-Loop Acceptance Protocol**).

Self-Modification

High
Category
Rogue Agent
Confidence
94% confidence
Finding

This section instructs how to load, enable, copy, and remove the patch skill within the agent/runtime skill system. That materially increases the skill's ability to modify its own operating environment and be invoked by other agents, expanding attack surface if the skill content is malicious or later replaced.

Content

Scanner excerpt · SKILL.en.md (reported line 79)May include surrounding context.

md
| **Use local AI tools only; do not load in OpenClaw** | Put `agent-feishu-direct-tools-patch` under **skills/rules/context** directories supported by your tool, or run by **@mention/pasting `SKILL.md` path** in chat; **do not** write it into `openclaw.json` `skills`. This way OpenClaw Gateway runtime **cannot see** this Skill at all. |
| **Temporarily load into OpenClaw** | If runtime **Gateway Agent** must read this doc: **temporarily** copy this directory into an existing folder under `skills.load.extraDirs`; **delete the copy after use** (or remove the extra directory added specifically for this patch), then **restart Gateway**. If it no longer appears in list, normal state is restored. |
| **Do not keep `enabled: true` long-term** | If config has `skills.entries.<name>`: do **not** keep this Skill permanently enabled; enable only when patching (if your OpenClaw version supports per-entry toggle), then switch back to **disabled** or remove the entry. |
| **Do not rely on "Agent auto-selects skill"** | Trigger explicitly with **one clear user sentence** (e.g., "apply openclaw-lark agent-feishu-direct-tools-patch"), avoiding mixing patch skill with daily always-on sets like `team-agent-onboarding`. |
| **Distribute via repo or archive** | Include the whole `agent-feishu-direct-tools-patch` directory in Git or package for reuse; whether runtime loads it is separate from whether files stay on disk — keeping files != must enable permanently in `skills.entries`. |

**Relation to §"Allow OpenClaw chat Agent to load this Skill"**: those items describe how to load when **short-term needed**; by default, still prefer **execute in AI-assisted dev tools + do not keep loaded in Gateway after use**, or **temporary load -> remove immediately after patch**.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
t-feishu-direct-tools-patch` 放在所用工具支持的 **skills / 规则 / 上下文** 目录,或在对话里 **@ / 粘贴 `SKILL.md` 路径** 执行;**不要**写入 `openclaw.json` 的 `skills`。这样 OpenClaw Gateway 运行时 **

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
t-feishu-direct-tools-patch` 放在所用工具支持的 **skills / 规则 / 上下文** 目录,或在对话里 **@ / 粘贴 `SKILL.md` 路径** 执行;**不要**写入 `openclaw.json` 的 `skills`。这样 OpenClaw Gateway 运行时 **

Self-Modification

High
Category
Rogue Agent
Confidence
88% confidence
Finding

This document explicitly instructs operators to load a patch skill into a runtime agent environment and even send the skill archive to a bot so it will automatically read and execute workflow instructions. That is a self-modifying/agent-directed code-change pattern: it expands the trust boundary, increases the chance of unintended code edits, and creates a path for prompt/instruction injection or unsafe autonomous modification of the OpenClaw/Lark integration.

Content

Scanner excerpt · doc/OpenClaw-Multi-Agent-Feishu-Direct-Tools-Patch-Guide-(openclaw-lark).en.md (reported line 172)May include surrounding context.

md
- "Apply `agent-feishu-direct-tools-patch` to patch `openclaw-lark`."
3. You can also send the skill archive file directly to the OpenClaw bot in Feishu chat; the bot will automatically read and execute the workflow instructions.
4. After execution, remove the temporary skill copy or disable the entry.
5. Restart Gateway so this patch skill does not remain as daily-chat noise.

Note: exposing SKILL to runtime agents only provides instructions; it does **not** replace actual code edits and restart.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill instructs use of npx -y @larksuite/openclaw-lark install without pinning an exact package version. That causes execution of whatever version is current in the registry at runtime, which is a supply-chain risk: a malicious update, compromised publisher account, or breaking release could execute arbitrary code during install or overwrite the plugin with unexpected content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This is a second occurrence of the same unpinned npx install instruction. Repeating the guidance in rollback/recovery steps increases the chance an operator will execute arbitrary newly-published code from the package registry during an incident, when scrutiny is already lower.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.en.md (reported line 49)May include surrounding context.

md
### When code editing can start

- **Required**: The user explicitly states agreement to execute this patch (e.g., "confirm execution", "start patching", "agree, modify according to Skill"; interpret equivalent expressions by locale).
- **Forbidden**: User only says "explain this Skill" / "what is this patch" without confirmation -> **explain only, do not edit files**.
- After confirmation, start from **§B**; throughout execution, still follow §0 completion reporting and restart notes in **"Patch and OpenClaw Runtime State"**.

---

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This occurrence again directs a live reinstall from npm without version pinning. In the context of a patch skill that already performs broad code modifications, an unpinned recovery command compounds risk by making the final system state dependent on mutable external registry content.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The deployment/validation section repeats the same unpinned package execution. Because this is presented as an official fallback after patch failure, operators may treat it as safe and execute it immediately, exposing the environment to supply-chain compromise or unintended code changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The rollback section again recommends an unpinned npx package install. Recovery paths are especially sensitive because they are likely to be executed under time pressure, making the mutable-latest behavior of npx particularly dangerous.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

If the manifest/front matter references the same unpinned package command, it embeds non-reproducible remote code execution guidance into the skill definition itself. That broadens exposure because automated tooling or users may trust manifest-level instructions as authoritative.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill instructs use of npx -y @larksuite/openclaw-lark install without pinning an exact package version. That allows the command to fetch whatever package version is current at execution time, creating supply-chain and reproducibility risk if a bad release, compromised package, or breaking update is published.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill body and operational instructions are presented in Chinese and direct the implementing agent to follow them as mandatory procedure, but the document does not offer the user any language or locale choice. This creates a language-policy concern because the skill effectively assumes a fixed language for execution guidance without documented opt-in or region-specific justification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This is another unpinned npx install command in operational guidance. Because npx resolves the latest matching package by default, the exact code executed later may differ from what was originally reviewed, enabling accidental or malicious supply-chain drift.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The repeated recommendation to reinstall via unpinned npx increases the chance an operator will execute arbitrary newer package code not covered by this skill's review. In a patching workflow, that is especially risky because it combines code modification with later remote package execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This deployment/rollback instruction again relies on an unpinned package execution path. If the package changes or is compromised, recovery steps could introduce new code into a sensitive gateway/plugin environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The rollback section repeats an unpinned package install command, preserving the same supply-chain risk during incident response or recovery. Recovery paths are high leverage because users may run them quickly under pressure without additional scrutiny.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The document recommends reinstalling the plugin via npx -y @larksuite/openclaw-lark install without pinning an exact package version. That causes execution of whatever package version is current at install time, which weakens reproducibility and creates a supply-chain risk if a bad release or dependency compromise occurs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The document instructs users to reinstall with npx -y @larksuite/openclaw-lark install without pinning a specific package version. That causes execution of whatever version is current on the registry at run time, which weakens supply-chain integrity and can unexpectedly introduce malicious or breaking changes during a recovery path. In this skill context, the risk is higher because the command is presented as a remediation step users may run under pressure after a failed patch.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document says a robot can automatically read and execute a skill zip sent in chat, but it does not pair that workflow with strong warnings about arbitrary code/instruction execution, privilege scope, or trust boundaries. In practice, this encourages a dangerous pattern where untrusted artifacts delivered over messaging can trigger system modifications, which is especially risky for an agent skill whose purpose is to patch source code and alter runtime behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file is explicitly an English-only skill variant (SKILL.en.md), but the instructions do not offer a language choice or explain why English is required. Under the policy rule, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
67% confidence
Finding

L004 表述为已提供英文版,但“如需使用,可自行重命名为 SKILL.md 替换当前中文版本”,显示当前默认生效的是中文版本。对语言/locale 政策而言,这种默认固定语言的方式未在使用点明确提供用户选择或 opt-in,可能导致语言偏好未被主动征询。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.