feishu-cli-platform
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the Feishu API, such as message contents and cloud documents. While this introduces a surface for indirect prompt injection, the skill's primary focus is on searching and displaying information rather than autonomous execution of data-derived instructions. Mandatory Evidence Chain: 1. Ingestion points: Search results for messages and docs (references/workflows/search/workflow.md). 2. Boundary markers: Not explicitly defined in instructions. 3. Capability inventory: Bash execution, curl, and file writing (SKILL.md). 4. Sanitization: Relies on jq and CLI tool output formatting.
- [COMMAND_EXECUTION]: The skill enables execution of the
feishu-clitool along with standard utilities likecurl,jq, andpython3. These tools are appropriately scoped to the skill's purpose of managing Feishu platform resources and do not exhibit malicious patterns.
Audit Metadata