lark-whiteboard

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill workflow requires the agent to write and execute custom Node.js scripts (e.g., generate-fishbone.js) to calculate coordinates for complex diagrams. This runtime generation and execution of code is a core feature but constitutes a dynamic execution risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches content from Lark documents using the lark-cli docs +fetch command. This untrusted external data is used to generate diagrams and layout scripts, creating a vulnerability surface where malicious instructions in documents could influence agent behavior.
  • Ingestion points: Data is fetched from documents via the lark-cli tool as described in SKILL.md and scenes/mermaid.md.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for data processed from documents.
  • Capability inventory: Includes file writing, script execution via node, and document updates via lark-cli.
  • Sanitization: The skill lacks explicit sanitization or validation steps for the content ingested from document URLs.
  • [EXTERNAL_DOWNLOADS]: The skill fetches and installs the official @larksuite/whiteboard-cli package from the NPM registry. This is a scoped package provided by a well-known technology organization.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands like npx, npm, and lark-cli to perform its tasks. It incorporates a mandatory pre-flight check and user confirmation step before executing commands that overwrite existing document data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 12:55 PM