skills/larksuite/cli/lark-doc/Gen Agent Trust Hub

lark-doc

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests content from external Feishu documents and Wiki pages via docs +fetch and mindnotes nodes list. This untrusted data is then processed by the agent for tasks like summarization, editing, and report generation.
  • Ingestion points: Identified in references/lark-doc-fetch.md and references/lark-doc-mindnote.md where external document content is retrieved.
  • Boundary markers: The instructions lack explicit directives for the agent to treat ingested document text as untrusted data or to disregard potential instructions embedded within the document body.
  • Capability inventory: The skill possesses extensive write capabilities, including local file creation via init-draft and document modifications through docs +create and docs +update.
  • Sanitization: The skill documents standard XML entity escaping (e.g., <, >) for text content in references/lark-doc-xml.md.
  • [COMMAND_EXECUTION]: The skill makes heavy use of the lark-cli binary to perform document operations. It dynamically constructs shell commands, often passing complex JSON structures via the --data or --presentation-decision flags.
  • [EXTERNAL_DOWNLOADS]: The skill downloads images, attachments, and cover art from remote HTTPS URLs via docs +media-download, docs +media-preview, and docs +resource-update.
  • Security Mitigations: The skill explicitly defines security boundaries for network operations in references/lark-doc-fetch.md and references/lark-doc-resource-cover.md, including the rejection of private, loopback, and link-local IP addresses, and the validation of redirects to prevent Server-Side Request Forgery (SSRF).
  • [DATA_EXFILTRATION]: In references/lark-doc-media-insert.md and references/lark-doc-resource-cover.md, the skill utilizes the --from-clipboard flag to access the system clipboard. While implemented for user-initiated image insertion, this provides the agent with a mechanism to access local data outside of the immediate workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:31 AM
Security Audit — agent-trust-hub — lark-doc