lark-workflow-meeting-summary

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted meeting transcripts and notes which could contain embedded malicious instructions.
  • Ingestion points: Meeting notes are fetched via lark-cli note +detail and transcripts via lark-cli minutes +detail --transcript as described in Step 3.
  • Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" warnings for the ingested content.
  • Capability inventory: The skill can write transcripts to the local filesystem (--output-dir ./transcripts) and update or create cloud documents (lark-cli docs +create/update) in Step 5.
  • Sanitization: There is no evidence of sanitization or filtering for the data retrieved from meeting notes before processing.
  • [COMMAND_EXECUTION]: The skill relies on complex shell command construction using the lark-cli tool.
  • Multiple commands like lark-cli vc +search, vc +detail, note +detail, minutes +detail, and docs +create/update are used throughout the workflow.
  • User-controlled or meeting-derived data (such as date strings, meeting IDs, note IDs, and content) are interpolated into these shell commands, creating a potential surface for command injection if the agent fails to escape inputs correctly.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:30 AM
Security Audit — agent-trust-hub — lark-workflow-meeting-summary