skills/larksuite/cli/lark-calendar/Gen Agent Trust Hub

lark-calendar

Pass

Audited by Gen Agent Trust Hub on May 27, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the lark-cli binary, which is a vendor-owned tool from 'larksuite' required for interacting with the Lark platform. The instructions also suggest the use of system commands or scripts for precise date and time conversions, which is a standard procedure for ensuring mathematical accuracy in scheduling tasks.
  • [DATA_EXPOSURE]: The skill manages sensitive calendar information, including event details, participant lists, and meeting room availability. It mitigates risk by enforcing a strict workflow that requires reading shared security and authentication guidelines, and by mandating human confirmation before any destructive or creative actions are finalized.
  • [PROMPT_INJECTION]: As the skill reads and processes external data from calendar events (summaries, descriptions), it has an inherent surface for indirect prompt injection. However, the skill provides clear delimiters and structured processing logic through CLI shortcuts to minimize the risk of the agent misinterpreting event content as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 27, 2026, 03:05 AM
Security Audit — agent-trust-hub — lark-calendar