lark-workflow-standup-report
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
lark-clito perform authenticated queries for calendar agendas and task lists. These operations are restricted to the user's own data and are necessary for the skill's core functionality of report generation. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources, specifically calendar event summaries and task descriptions, which could theoretically contain malicious instructions.
- Ingestion points: Data enters the context via the output of
lark-cli calendar +agendaandlark-cli task +get-my-tasks. - Boundary markers: No explicit delimiters are used to wrap the tool outputs in the prompt instructions.
- Capability inventory: The skill's capabilities are limited to data transformation, sorting, and markdown report generation; it does not perform destructive actions or network exfiltration.
- Sanitization: There is no explicit sanitization of the retrieved text content, though the transformation into a markdown table provides a structured format.
Audit Metadata