feishu-im-read

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were identified in this skill. The skill is designed for interacting with the Feishu (Lark) IM API to retrieve messages and download files. All tool invocations and parameters described are consistent with legitimate API usage.
  • [PROMPT_INJECTION]: While the skill processes untrusted data from external chat messages (ingestion points: feishu_im_user_get_messages, feishu_im_user_search_messages), which is an inherent surface for indirect prompt injection, there are no instructions that would cause the agent to bypass its own safety guidelines. The capabilities are limited to message retrieval and resource downloading (feishu_im_user_fetch_resource), with no high-risk capabilities like arbitrary code execution or filesystem modification. No explicit boundary markers or sanitization logic are defined in this instruction file, which is typical for data-retrieval skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 04:29 AM