feishu-mcp
飞书MCP集成技能文档中存在硬编码凭证泄露(appSecret明文暴露),可能引导用户将敏感信息写入配置文件,存在凭证外泄风险
appSecret 'BiL8CymBwxiA998MXxvUKbN23RhPsxAg' 和 appID 'cli_a926728f3e38dcba' 以明文形式直接写在 SKILL.md 公开文档中,任何获取此技能的用户都能查看和复制这些凭证
SKILL.md:22 Why this conclusion was reached
1/4 dimensions flaggedDeclared resources and inferred behavior are broadly aligned.
2 lower-risk artifacts were extracted and still need context.
The report includes 0 attack-chain steps and 2 severe findings.
Dependency information is incomplete, so supply-chain confidence stays limited.
What drove the risk score up
appSecret 'BiL8CymBwxiA998MXxvUKbN23RhPsxAg' 明文暴露在公开文档中
要求用户将 appSecret 写入 ~/.openclaw/openclaw.json 配置文件
文档未警告凭证的敏感性和安全存储方式
Most important evidence
硬编码凭证泄露
appSecret 'BiL8CymBwxiA998MXxvUKbN23RhPsxAg' 和 appID 'cli_a926728f3e38dcba' 以明文形式直接写在 SKILL.md 公开文档中,任何获取此技能的用户都能查看和复制这些凭证
SKILL.md:22 引导用户写入明文凭证
SKILL.md 指导用户将 appSecret 直接写入配置文件 ~/.openclaw/openclaw.json,这种做法增加了凭证泄露风险
SKILL.md:21 缺少凭证安全警告
文档未包含任何关于凭证保管安全性的警告或最佳实践说明
SKILL.md:1 Declared capability vs actual capability
SKILL.md 仅包含配置说明文档,无文件读写代码 文档说明 MCP 工具使用飞书 OpenAPI 进行文档操作 无 shell 命令执行代码 Suspicious artifacts and egress
https://feishu-openai-mcp-proxy.bytedance.net/mcp SKILL.md:21
https://xxx.feishu.cn/docx/ABC123def SKILL.md:121
Dependencies and supply chain
There are no structured dependency warnings.
File composition
SKILL.md