lark-openapi-explorer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill dynamically fetches documentation using
WebFetchfromopen.feishu.cnandopen.larksuite.comto discover API endpoints and parameters, which are then executed vialark-cli api. - Ingestion points: WebFetch operations in Step 2, Step 3, and Step 4 within
SKILL.md. - Boundary markers: Absent. There are no explicit constraints or delimiters instructing the model to disregard natural language commands embedded in the fetched documentation.
- Capability inventory: Execution of arbitrary Lark OpenAPI requests using
lark-cli apiin Step 5. - Sanitization: Absent. Parameters and paths from the external files are directly interpolated into the
lark-clicommand line structure.
Audit Metadata