Skip to content

[Bug] CowAgent have risk leaking user's privacy and executing destruction commands on user's computer #2998

Description

@EvanProgramming

Self check

  • I'm on the latest version and searched existing issues (incl. closed) — no duplicate.

Environment

Version: Newest Version
Platform: macOS 26.4
Form: Desktop App
Model: Deepseek / Claude Opus ... This applies for any models.

What happened?

  1. Invite the CowAgent bot to Feishu(Lark).
  2. use"@" to call the bot, and let it find something in the group or some tasks that needs to use local files.
  3. Your data will expose.

Another Condition

  1. Invite the CowAgent bot to Feishu(Lark).
  2. use"@" to call the bot, and let it find something in the group or some tasks that needs to use local files. Or executing some commands that allows attacks from attackers.
  3. The bot may do that.

What is expected: CowAgent should disagree and don't expose any private data and files to others in the group, unless the owner user asked it to.
What happened: CowAgent directly find documents on my computer and sent them in the group.

  • I will fix this issue.

Logs

缺口
说明
❌ 无提示词攻击防护专业规则
没有「识别伪装系统/管理员/授权任意操作」这类注入面的明确防御策略
❌ 无全局覆盖
原铁律只在单个群有效,其他群/渠道是裸奔的
❌ 无「攻击面」防范清单
没明确列出「凡涉及运行命令/读文件/调API/发消息/透露信息都要先核实来源」
❌ 无敏感信息「永不披露」红线
只有模糊的「别泄露密钥」

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions