nature-experiment-log

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the lark-cli command-line tool to interface with Feishu (Lark) for retrieving messages and downloading experimental attachments. This is an intended integration for data collection.
  • [DATA_EXPOSURE]: The skill accesses local file systems to read experimental materials and write structured logs. It also retrieves message content and resources from Feishu groups when the optional integration is active. These actions are restricted to the directories and chat IDs specified by the user.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes untrusted data from external sources (Feishu messages, user-uploaded images, and voice transcripts).
  • Ingestion points: Raw experimental materials uploaded via session, local folder paths, and messages/attachments fetched from Feishu groups via lark-cli.
  • Boundary markers: The instructions do not explicitly define boundary markers for the LLM to ignore instructions within experimental data, though it emphasizes that the agent should only extract structural information.
  • Capability inventory: The agent has capabilities to write files to the local disk/Obsidian vault and execute specific lark-cli commands for network retrieval.
  • Sanitization: Standard LLM guardrails are assumed; the skill instructions direct the agent to confirm ambiguous information with the user rather than executing based on potentially conflicting instructions in data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 08:16 AM
Security Audit — agent-trust-hub — nature-experiment-log