feishu-doc-optimizer
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads content from external Feishu documents and processes it to generate optimized versions, creating a surface for indirect prompt injection where instructions embedded in the source document could override the agent's behavior.
- Ingestion points: Raw content is retrieved from Feishu documents using the
scripts/feishu_doc_reader.pyscript. - Boundary markers: The workflow lacks explicit delimiters or instructions to ignore embedded commands within the ingested document body.
- Capability inventory: The skill possesses the ability to overwrite documents via browser automation in
scripts/feishu_doc_editor.py. - Sanitization: No sanitization or validation is performed on the ingested document content before it is passed to the agent for processing.
- [COMMAND_EXECUTION]: The skill requires the execution of local Python scripts to interact with the Feishu API and automate browser actions.
- The script
scripts/feishu_doc_editor.pyconnects to a local browser instance using the Chrome DevTools Protocol (CDP) on port 18800. - The script hardcodes the tenant domain
opencaio.feishu.cnfor document navigation, which may conflict with documents located on other Feishu tenants.
Audit Metadata