lark-okr
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from Lark OKR entities, including objectives, key results, progress records, and comments, which could contain malicious instructions designed to manipulate agent behavior. \n- Ingestion points: Untrusted data enters the agent context through several commands described in SKILL.md and references, such as
+cycle-detail,+comment-list,+comment-detail, and+progress-list. \n- Boundary markers: The instruction set lacks explicit boundary markers or instructions to the agent to treat data retrieved from Lark as potentially untrusted or to ignore embedded instructions. \n- Capability inventory: The skill possesses significant write capabilities, including creating and modifying OKR content, comments, and progress records across a user's account via thelark-cli. \n- Sanitization: There is no evidence of content sanitization, filtering, or validation for the data retrieved from Lark APIs before it is used to inform further agent actions.
Audit Metadata