feishu-update-doc
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it allows the agent to write arbitrary Markdown content to external Feishu cloud documents.
- Ingestion points: Untrusted data enters the agent context through the
markdown,new_title,selection_with_ellipsis, andselection_by_titleparameters defined inSKILL.md. - Boundary markers: The documentation does not define specific boundary markers or instructions for the agent to ignore potentially malicious embedded content within the
markdownpayload. - Capability inventory: The skill has the capability to write, overwrite, and delete content in external documents via the Feishu API.
- Sanitization: There is no evidence of sanitization, escaping, or validation of the input Markdown text within the skill description.
Audit Metadata