lark-approval

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data provided by the Lark/Feishu API, such as approval definitions, form values, and task comments. This content is generated by other users and represents a surface for indirect prompt injection. While the skill includes logic to validate form structures and types (e.g., distinguishing between input, date, and leaveGroupV2), it does not explicitly define boundary markers or sanitization for the natural language content within those fields.
  • [COMMAND_EXECUTION]: The skill legitimately uses the lark-cli binary to interact with the Lark platform. It provides clear guidance on using flags like --as user for proper authorization and --dry-run to preview actions before execution, which serves as a safety control for high-risk write operations such as approving or rejecting tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:56 AM
Security Audit — agent-trust-hub — lark-approval