lark-sheets
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a local binary
lark-clito perform operations on Lark spreadsheets. The included Python helper scripts (e.g.,scripts/lark_sheet_read_cli.py) execute this binary using thesubprocess.runfunction. The implementation correctly passes arguments as a list and avoids the use ofshell=True, which is a secure practice to prevent command injection. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and process data from external spreadsheets, which represents an attack surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent's context through tools like
+csv-get,+table-get, and+cells-get(documented inreferences/lark-sheets-read-data.md), as well as via thescripts/lark_profile_table.pyscript. - Boundary markers: The instructions guide the agent on how to interpret table structures using
annotated_csvwith row prefixes, but they do not provide explicit delimiters or "ignore instructions" warnings for the data being read. - Capability inventory: The skill possesses significant capabilities, including reading and writing spreadsheet data, creating pivot tables and charts, and performing administrative tasks on the workbook structure via
lark-clicalls inscripts/lark_sheet_read_cli.py. - Sanitization: The skill relies on standard data parsing (CSV, JSON) and does not perform additional sanitization or filtering of cell content to detect or neutralize embedded instructions.
Audit Metadata