feishu
Pass
Audited by Gen Agent Trust Hub on Jun 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to runcurlfor API requests andjqfor parsing JSON responses. - [EXTERNAL_DOWNLOADS]: Network traffic is directed to the official Feishu Open Platform API (
open.feishu.cn), which is a well-known and trusted service domain. - [PROMPT_INJECTION]: The skill ingests untrusted data from Feishu documents and IM messages (ingestion points) using the
Bashtool (capability inventory). It employsjqfor structured data parsing (sanitization) and includes explicit notes to confirm destructive or outward-facing actions with the user (boundary markers).
Audit Metadata