lark-meeting
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted meeting data which presents a surface for indirect prompt injection.
- Ingestion points: The skill reads transcripts, shared documents, and live event streams via
minutes +detail,docs +fetch, andvc +meeting-events. - Boundary markers: No explicit delimiters are required in the instructions to isolate external content from agent instructions.
- Capability inventory: The agent can perform write operations such as sending meeting messages, reactions, and updating meeting summaries or titles.
- Sanitization: No explicit sanitization or filtering of ingested meeting content is mandated before processing.
Audit Metadata