skills/larksuite/cli/lark-task/Gen Agent Trust Hub

lark-task

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external task records (summaries, descriptions, and comments) which could contain malicious instructions designed to subvert the agent's logic.
  • Ingestion points: Untrusted content enters the agent's context through several commands described in references/lark-task-get-my-tasks.md, references/lark-task-get-related-tasks.md, and references/lark-task-search.md.
  • Boundary markers: The instructions lack specific delimiters or "ignore embedded instructions" warnings when presenting task data to the AI model.
  • Capability inventory: The skill has significant write permissions, including the ability to create/modify tasks and upload local files using lark-cli as documented in references/lark-task-upload-attachment.md.
  • Sanitization: No sanitization or filtering is applied to the metadata or content retrieved from the Lark API before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:31 AM
Security Audit — agent-trust-hub — lark-task