feishu-mcp
SKILL.md exposes hardcoded credentials (appID and appSecret) for a Feishu application in plaintext, representing critical credential leakage.
The appSecret 'BiL8CymBwxiA998MXxvUKbN23RhPsxAg' is hardcoded in plaintext within SKILL.md. If these are real credentials, they can be harvested and used to access the associated Feishu application with document permissions.
SKILL.md:23 Why this conclusion was reached
2/4 dimensions flagged1 undeclared or violating capabilities were inferred.
2 lower-risk artifacts were extracted and still need context.
The report includes 3 attack-chain steps and 2 severe findings.
Dependency information is incomplete, so supply-chain confidence stays limited.
Attack Chain
Impact · SKILL.md:22
exploitation · SKILL.md:23
Impact · SKILL.md:21
What drove the risk score up
appSecret 'BiL8CymBwxiA998MXxvUKbN23RhPsxAg' exposed in plaintext at line 23
appID 'cli_a926728f3e38dcba' also exposed in plaintext
SKILL.md provides no guidance on credential protection
Most important evidence
Hardcoded Application Secret Exposed
The appSecret 'BiL8CymBwxiA998MXxvUKbN23RhPsxAg' is hardcoded in plaintext within SKILL.md. If these are real credentials, they can be harvested and used to access the associated Feishu application with document permissions.
SKILL.md:23 Hardcoded Application ID Exposed
The appID 'cli_a926728f3e38dcba' is exposed in plaintext documentation.
SKILL.md:22 External Network Endpoint Referenced
The skill references an external ByteDance/Feishu endpoint for MCP operations.
SKILL.md:21 Declared capability vs actual capability
SKILL.md line 21: https://feishu-openai-mcp-proxy.bytedance.net/mcp SKILL.md lines 22-23: hardcoded appID and appSecret Suspicious artifacts and egress
https://feishu-openai-mcp-proxy.bytedance.net/mcp SKILL.md:21
https://xxx.feishu.cn/docx/ABC123def SKILL.md:121
Dependencies and supply chain
There are no structured dependency warnings.
File composition
SKILL.md