feishu-doc

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external Feishu (Lark) documents, which is a common attack surface for indirect prompt injection.
  • Ingestion points: External document content is fetched via the readDoc function in index.js, which aggregates data from Docs, Sheets, and Bitable APIs.
  • Boundary markers: The fetched content is converted to Markdown and returned to the agent without specific delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill has significant write capabilities, including creating documents (create.js), writing/appending to documents (index.js), and downloading files to the local file system (download_file.js).
  • Sanitization: While input_guard.js provides sanitization for data being sent to Feishu, there is no corresponding mechanism to neutralize potential prompt injections in the data received from Feishu.
  • [DATA_EXPOSURE]: The authentication module in lib/auth.js implements a file-based token cache located at ../../../memory/feishu_token.json. This mechanism persists sensitive tenant_access_token data to a shared path to allow multiple related skills to share authentication, which represents a centralized point for potential credential exposure if the shared directory is compromised.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:24 AM
Security Audit — agent-trust-hub — feishu-doc