feishu-doc
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external Feishu (Lark) documents, which is a common attack surface for indirect prompt injection.
- Ingestion points: External document content is fetched via the
readDocfunction inindex.js, which aggregates data from Docs, Sheets, and Bitable APIs. - Boundary markers: The fetched content is converted to Markdown and returned to the agent without specific delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill has significant write capabilities, including creating documents (
create.js), writing/appending to documents (index.js), and downloading files to the local file system (download_file.js). - Sanitization: While
input_guard.jsprovides sanitization for data being sent to Feishu, there is no corresponding mechanism to neutralize potential prompt injections in the data received from Feishu. - [DATA_EXPOSURE]: The authentication module in
lib/auth.jsimplements a file-based token cache located at../../../memory/feishu_token.json. This mechanism persists sensitivetenant_access_tokendata to a shared path to allow multiple related skills to share authentication, which represents a centralized point for potential credential exposure if the shared directory is compromised.
Audit Metadata