feishu-doc-reader

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions include commands to change file permissions (chmod +x) on local scripts (scripts/read_doc.sh, scripts/get_blocks.sh). This is standard setup for local execution but involves modifying file attributes.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest untrusted data from external Feishu documents.
  • Ingestion points: Document content is fetched via scripts/read_feishu_doc.py and scripts/get_feishu_doc_blocks.py.
  • Boundary markers: None identified in the provided documentation to differentiate between instructions and data.
  • Capability inventory: The skill executes local shell and Python scripts to perform network operations (curl) and data processing.
  • Sanitization: No explicit sanitization of document content is mentioned before the data is processed or returned to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 02:09 AM