lark-workflow-form-builder

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the lark-cli binary to perform operations on the Lark platform.
  • Evidence: The workflow involves executing commands such as lark-cli base +table-create, lark-cli base +form-create, and lark-cli im +messages-send to automate form management and distribution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes natural language input from users to generate JSON schemas for form fields, which represents a potential injection surface.
  • Ingestion points: User-provided descriptions of form requirements are used to design field schemas.
  • Boundary markers: The skill lacks explicit prompt delimiters but includes a mandatory instruction for the AI to confirm the designed schema with the user before proceeding.
  • Capability inventory: The skill possesses extensive write capabilities to a corporate communication platform via lark-cli, including creating tables and sending messages.
  • Sanitization: No explicit sanitization or validation of the AI-generated schema is described within the skill instructions, relying instead on the user review step.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:54 PM