feishu-doc-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads content from external Feishu documents and processes it to generate optimized versions, creating a surface for indirect prompt injection where instructions embedded in the source document could override the agent's behavior.
  • Ingestion points: Raw content is retrieved from Feishu documents using the scripts/feishu_doc_reader.py script.
  • Boundary markers: The workflow lacks explicit delimiters or instructions to ignore embedded commands within the ingested document body.
  • Capability inventory: The skill possesses the ability to overwrite documents via browser automation in scripts/feishu_doc_editor.py.
  • Sanitization: No sanitization or validation is performed on the ingested document content before it is passed to the agent for processing.
  • [COMMAND_EXECUTION]: The skill requires the execution of local Python scripts to interact with the Feishu API and automate browser actions.
  • The script scripts/feishu_doc_editor.py connects to a local browser instance using the Chrome DevTools Protocol (CDP) on port 18800.
  • The script hardcodes the tenant domain opencaio.feishu.cn for document navigation, which may conflict with documents located on other Feishu tenants.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 08:38 AM
Security Audit — agent-trust-hub — feishu-doc-optimizer