feishu-doc-reader
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions include commands to change file permissions (
chmod +x) on local scripts (scripts/read_doc.sh,scripts/get_blocks.sh). This is standard setup for local execution but involves modifying file attributes. - [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest untrusted data from external Feishu documents.
- Ingestion points: Document content is fetched via
scripts/read_feishu_doc.pyandscripts/get_feishu_doc_blocks.py. - Boundary markers: None identified in the provided documentation to differentiate between instructions and data.
- Capability inventory: The skill executes local shell and Python scripts to perform network operations (
curl) and data processing. - Sanitization: No explicit sanitization of document content is mentioned before the data is processed or returned to the agent context.
Audit Metadata