[Bug] CowAgent have risk leaking user's privacy and executing destruction commands on user's computer
Author: EvanProgrammingCreated Jul 31, 2026Updated Aug 16, 2026
Self check
- I'm on the latest version and searched existing issues (incl. closed) — no duplicate.
Environment
Version: Newest Version Platform: macOS 26.4 Form: Desktop App Model: Deepseek / Claude Opus ... This applies for any models.
What happened?
- Invite the CowAgent bot to Feishu(Lark).
- use"@" to call the bot, and let it find something in the group or some tasks that needs to use local files.
- Your data will expose.
Another Condition
- Invite the CowAgent bot to Feishu(Lark).
- use"@" to call the bot, and let it find something in the group or some tasks that needs to use local files. Or executing some commands that allows attacks from attackers.
- The bot may do that.
What is expected: CowAgent should disagree and don't expose any private data and files to others in the group, unless the owner user asked it to. What happened: CowAgent directly find documents on my computer and sent them in the group.
- I will fix this issue.
Logs
缺口
说明
❌ 无提示词攻击防护专业规则
没有「识别伪装系统/管理员/授权任意操作」这类注入面的明确防御策略
❌ 无全局覆盖
原铁律只在单个群有效,其他群/渠道是裸奔的
❌ 无「攻击面」防范清单
没明确列出「凡涉及运行命令/读文件/调API/发消息/透露信息都要先核实来源」
❌ 无敏感信息「永不披露」红线
只有模糊的「别泄露密钥」
Source: zhayujie/CowAgent