lark-openapi-explorer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill dynamically fetches documentation using WebFetch from open.feishu.cn and open.larksuite.com to discover API endpoints and parameters, which are then executed via lark-cli api.
  • Ingestion points: WebFetch operations in Step 2, Step 3, and Step 4 within SKILL.md.
  • Boundary markers: Absent. There are no explicit constraints or delimiters instructing the model to disregard natural language commands embedded in the fetched documentation.
  • Capability inventory: Execution of arbitrary Lark OpenAPI requests using lark-cli api in Step 5.
  • Sanitization: Absent. Parameters and paths from the external files are directly interpolated into the lark-cli command line structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:30 AM
Security Audit — agent-trust-hub — lark-openapi-explorer