add-feishu
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill introduces an input surface for untrusted data from the Feishu/Lark messaging platform.
- Ingestion points:
src/channels/feishu.tsimplementshandleMessage, which ingests message content directly from the Feishu WebSocket event (im.message.receive_v1). - Boundary markers: The skill does not implement specific boundary markers or "ignore instructions" wrappers for the ingested content before it is passed to the agent loop.
- Capability inventory: The core
src/index.tslogic demonstrates that the agent has the capability to execute tasks viarunContainerAgent, which performs operations within a container environment. - Sanitization: Input is parsed for JSON structure (expected for Feishu text messages), but the resulting text content is passed to the agent without further sanitization or filtering of prompt-like instructions.
- Risk Factor: The skill explicitly configures the registration in
SKILL.mdwithrequires_trigger = 0, meaning the bot will process and respond to all messages in a chat without requiring an explicit mention or trigger, maximizing the exposure to potentially malicious user-provided input.
Audit Metadata