lark-calendar
Pass
Audited by Gen Agent Trust Hub on May 27, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
lark-clibinary, which is a vendor-owned tool from 'larksuite' required for interacting with the Lark platform. The instructions also suggest the use of system commands or scripts for precise date and time conversions, which is a standard procedure for ensuring mathematical accuracy in scheduling tasks. - [DATA_EXPOSURE]: The skill manages sensitive calendar information, including event details, participant lists, and meeting room availability. It mitigates risk by enforcing a strict workflow that requires reading shared security and authentication guidelines, and by mandating human confirmation before any destructive or creative actions are finalized.
- [PROMPT_INJECTION]: As the skill reads and processes external data from calendar events (summaries, descriptions), it has an inherent surface for indirect prompt injection. However, the skill provides clear delimiters and structured processing logic through CLI shortcuts to minimize the risk of the agent misinterpreting event content as instructions.
Audit Metadata