lark-workflow-standup-report

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes lark-cli to perform authenticated queries for calendar agendas and task lists. These operations are restricted to the user's own data and are necessary for the skill's core functionality of report generation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources, specifically calendar event summaries and task descriptions, which could theoretically contain malicious instructions.
  • Ingestion points: Data enters the context via the output of lark-cli calendar +agenda and lark-cli task +get-my-tasks.
  • Boundary markers: No explicit delimiters are used to wrap the tool outputs in the prompt instructions.
  • Capability inventory: The skill's capabilities are limited to data transformation, sorting, and markdown report generation; it does not perform destructive actions or network exfiltration.
  • Sanitization: There is no explicit sanitization of the retrieved text content, though the transformation into a markdown table provides a structured format.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:30 AM
Security Audit — agent-trust-hub — lark-workflow-standup-report