feishu-pm

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary logic is focused on interacting with the official Feishu API domain (open.feishu.cn). All operations are consistent with its stated purpose of managing project tasks.
  • [PROMPT_INJECTION]: The skill formats data retrieved from Feishu tables directly into markdown tables. While this presents an indirect prompt injection surface common to data-processing tools, the skill lacks dangerous capabilities such as shell execution or file-system modifications, making the risk negligible.
  • [DATA_EXFILTRATION]: Network operations are restricted to the official service domain for Feishu/Lark. No sensitive local configuration files or credentials from the host environment are accessed or transmitted to external servers.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 11:29 AM