feishu-pm
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary logic is focused on interacting with the official Feishu API domain (open.feishu.cn). All operations are consistent with its stated purpose of managing project tasks.
- [PROMPT_INJECTION]: The skill formats data retrieved from Feishu tables directly into markdown tables. While this presents an indirect prompt injection surface common to data-processing tools, the skill lacks dangerous capabilities such as shell execution or file-system modifications, making the risk negligible.
- [DATA_EXFILTRATION]: Network operations are restricted to the official service domain for Feishu/Lark. No sensitive local configuration files or credentials from the host environment are accessed or transmitted to external servers.
Audit Metadata