lark-approval
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data provided by the Lark/Feishu API, such as approval definitions, form values, and task comments. This content is generated by other users and represents a surface for indirect prompt injection. While the skill includes logic to validate form structures and types (e.g., distinguishing between
input,date, andleaveGroupV2), it does not explicitly define boundary markers or sanitization for the natural language content within those fields. - [COMMAND_EXECUTION]: The skill legitimately uses the
lark-clibinary to interact with the Lark platform. It provides clear guidance on using flags like--as userfor proper authorization and--dry-runto preview actions before execution, which serves as a safety control for high-risk write operations such as approving or rejecting tasks.
Audit Metadata