feishu-doc

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides the ability to read content from external Feishu documents and comments through actions like read, list_blocks, and list_comments. This untrusted data is ingested directly into the agent's context.
  • Ingestion points: The feishu_doc tool in SKILL.md consumes external data via actions: read, list_blocks, get_block, list_comments, get_comment, and list_comment_replies.
  • Boundary markers: There are no instructions provided in the skill to use delimiters or specific warnings to ignore instructions embedded within the document content.
  • Capability inventory: The skill includes significant write and modification capabilities across SKILL.md and references/block-types.md, including write (replace all), append, update_block, delete_block, and create_comment.
  • Sanitization: The instructions do not mention any sanitization, filtering, or validation of the content retrieved from Feishu before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:15 AM
Security Audit — agent-trust-hub — feishu-doc