lark-task
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external task records (summaries, descriptions, and comments) which could contain malicious instructions designed to subvert the agent's logic.
- Ingestion points: Untrusted content enters the agent's context through several commands described in
references/lark-task-get-my-tasks.md,references/lark-task-get-related-tasks.md, andreferences/lark-task-search.md. - Boundary markers: The instructions lack specific delimiters or "ignore embedded instructions" warnings when presenting task data to the AI model.
- Capability inventory: The skill has significant write permissions, including the ability to create/modify tasks and upload local files using
lark-clias documented inreferences/lark-task-upload-attachment.md. - Sanitization: No sanitization or filtering is applied to the metadata or content retrieved from the Lark API before it is processed by the agent.
Audit Metadata