lark-doc
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests content from external Feishu documents and Wiki pages via
docs +fetchandmindnotes nodes list. This untrusted data is then processed by the agent for tasks like summarization, editing, and report generation. - Ingestion points: Identified in
references/lark-doc-fetch.mdandreferences/lark-doc-mindnote.mdwhere external document content is retrieved. - Boundary markers: The instructions lack explicit directives for the agent to treat ingested document text as untrusted data or to disregard potential instructions embedded within the document body.
- Capability inventory: The skill possesses extensive write capabilities, including local file creation via
init-draftand document modifications throughdocs +createanddocs +update. - Sanitization: The skill documents standard XML entity escaping (e.g.,
<,>) for text content inreferences/lark-doc-xml.md. - [COMMAND_EXECUTION]: The skill makes heavy use of the
lark-clibinary to perform document operations. It dynamically constructs shell commands, often passing complex JSON structures via the--dataor--presentation-decisionflags. - [EXTERNAL_DOWNLOADS]: The skill downloads images, attachments, and cover art from remote HTTPS URLs via
docs +media-download,docs +media-preview, anddocs +resource-update. - Security Mitigations: The skill explicitly defines security boundaries for network operations in
references/lark-doc-fetch.mdandreferences/lark-doc-resource-cover.md, including the rejection of private, loopback, and link-local IP addresses, and the validation of redirects to prevent Server-Side Request Forgery (SSRF). - [DATA_EXFILTRATION]: In
references/lark-doc-media-insert.mdandreferences/lark-doc-resource-cover.md, the skill utilizes the--from-clipboardflag to access the system clipboard. While implemented for user-initiated image insertion, this provides the agent with a mechanism to access local data outside of the immediate workspace.
Audit Metadata