lark-workflow-form-builder
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
lark-clibinary to perform operations on the Lark platform. - Evidence: The workflow involves executing commands such as
lark-cli base +table-create,lark-cli base +form-create, andlark-cli im +messages-sendto automate form management and distribution. - [INDIRECT_PROMPT_INJECTION]: The skill processes natural language input from users to generate JSON schemas for form fields, which represents a potential injection surface.
- Ingestion points: User-provided descriptions of form requirements are used to design field schemas.
- Boundary markers: The skill lacks explicit prompt delimiters but includes a mandatory instruction for the AI to confirm the designed schema with the user before proceeding.
- Capability inventory: The skill possesses extensive write capabilities to a corporate communication platform via
lark-cli, including creating tables and sending messages. - Sanitization: No explicit sanitization or validation of the AI-generated schema is described within the skill instructions, relying instead on the user review step.
Audit Metadata