lark-workflow-meeting-summary
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted meeting transcripts and notes which could contain embedded malicious instructions.
- Ingestion points: Meeting notes are fetched via
lark-cli note +detailand transcripts vialark-cli minutes +detail --transcriptas described in Step 3. - Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" warnings for the ingested content.
- Capability inventory: The skill can write transcripts to the local filesystem (
--output-dir ./transcripts) and update or create cloud documents (lark-cli docs +create/update) in Step 5. - Sanitization: There is no evidence of sanitization or filtering for the data retrieved from meeting notes before processing.
- [COMMAND_EXECUTION]: The skill relies on complex shell command construction using the
lark-clitool. - Multiple commands like
lark-cli vc +search,vc +detail,note +detail,minutes +detail, anddocs +create/updateare used throughout the workflow. - User-controlled or meeting-derived data (such as date strings, meeting IDs, note IDs, and content) are interpolated into these shell commands, creating a potential surface for command injection if the agent fails to escape inputs correctly.
Audit Metadata