lark-whiteboard
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill provides JavaScript templates (e.g., in
scenes/fishbone.md,scenes/flywheel.md, andscenes/treemap.md) that the agent is instructed to write to local files (.cjs) and execute usingnode. This is used to perform geometric and math calculations for complex diagram layouts. - [EXTERNAL_DOWNLOADS]: The skill instructs the agent to run
@larksuite/whiteboard-clivianpx. As this is a resource owned by the vendor (larksuite), it is considered an intended dependency for the skill's operation. - [COMMAND_EXECUTION]: The skill relies on shell command execution for its core functionality, specifically calling
lark-clifor platform interactions andnodefor running the aforementioned layout scripts. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided data, such as diagram labels, descriptions, and data points, which are then interpolated into script templates and DSL JSON. This creates a surface for indirect prompt injection, as malicious input could attempt to manipulate the generated script or the final whiteboard content.
Audit Metadata