Atlas / Skills / larksuite / Lark Calendar

Lark CalendarBLOCK

skills/larksuite/lark-calendar

The official Lark/飞书 CLI tool, maintained by the larksuite team — built for humans and AI Agents. Covers core business domains including Messenger, Docs, Base, Sheets, Calendar, Mail, Tasks, Meetings, and more, with 200+ commands and 20+ AI Agent Skills.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
1.0.0
Hosts
—
License
MIT
Stars
17,544
01

Overview

The official Lark/飞书 CLI tool, maintained by the larksuite team — built for humans and AI Agents. Covers core business domains including Messenger, Docs, Base, Sheets, Calendar, Mail, Tasks, Meetings, and more, with 200+ commands and 20+ AI Agent Skills.

Read from source at commit 91a26abd3925OBSERVED · 2026-10-07
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: lark-calendar
version: 1.0.0
description: "飞书日历:管理日历日程和会议室。查看/搜索日程、创建/更新日程、管理参会人、查询忙闲和推荐时段、预定会议室。当用户需要查看日程安排、创建/修改会议、查询/预定会议室时使用。不负责:查询过去的视频会议记录(走 lark-meeting)、待办任务(走 lark-task)。"
metadata:
  requires:
    bins: ["lark-cli"]
  cliHelp: "lark-cli calendar --help"
---

# calendar (v4)

开始前先读 [`../lark-shared/SKILL.md`](../lark-shared/SKILL.md)(认证、权限处理)。

**CRITICAL — 凡涉及预约日程/会议室、调整时间或查询/搜索会议室,第一步 MUST 读 [`references/lark-calendar-schedule-meeting.md`](references/lark-calendar-schedule-meeting.md)。仅编辑字段(改标题/描述)或增删参会人(不涉及时间和会议室)时可跳过,直接读 [`references/lark-calendar-update.md`](references/lark-calendar-update.md)。**

## 身份

按**日程归属**选身份:

- 查看/管理登录用户本人的日程 → `--as user`(默认,绝大多数场景)。
- 查看/管理 bot 自己创建/拥有的日程 → `--as bot`

**对话人称映射**:「我」= 登录用户,「你」= 应用(bot);作为字段取值的人称(参会人、会议 owner 等)不参与身份判定,如「你创建日程,邀请我、会议 owner 为我」→ `--as bot` 创建,登录用户仅作参会人与会议 owner。

```bash
# 用户本人日程 → user
lark-cli calendar +agenda --as user
# bot 自建或参与的日程 → bot
lark-cli calendar +agenda --as bot
```

## Shortcuts

| Shortcut | 说明 |
|----------|------|
| `+agenda` | 查看日程安排(默认今天) |
| [`+meeting`](references/lark-calendar-meeting.md) | 通过日程事件 ID 获取关联的视频会议信息(meeting_id、meeting_note),日程开过视频会议才会有meeting_id,**注意**: 视频会议链接获取走+get命令 |
| [`+create`](references/lark-calendar-create.md) | 创建日程并邀请参会人(ISO 8601 时间) |
| [`+update`](references/lark-calendar-update.md) | 更新既有日程字段,或独立增量添加/移除参会人和会议室;重复性日程/例外必须传 `--apply-to`(详见 [重复性日程操作规范](references/lark-calendar-recurring.md)) |
| `+delete` | 删除日程;重复性日程/例外必须传 `--apply-to`(详见 [重复性日程操作规范](references/lark-calendar-recurring.md)) |
| `+freebusy` | 查询主日历的忙闲/RSVP状态/空闲时间段。(**如需预约/推荐时间段**走 `+suggestion`——它综合工作时间、忙碌区间和休息时间推荐。) |
| [`+room-find`](references/lark-calendar-room-find.md) | 针对一个或多个**明确的**时间块查找可用会议室(无明确时间时禁止直接调用,需先走 +suggestion) |
| [`+rsvp`](references/lark-calendar-rsvp.md) | 回复日程(接受/拒绝/待定) |
| [`+join-event`](references/lark-calendar-join-event.md) | 凭分享 token 加入日程(分享链接/二维码/分享卡片/RSVP 卡片) |
| [`+suggestion`](references/lark-calendar-suggestion.md) | 根据非明确时间或一段时间范围,推荐多个可用时间块方案 |
| [`+transfer`](references/lark-calendar-transfer.md) | 把日程组织者转让给另一个用户或机器人;不可逆,需 `--yes` |
| [`+list-attendees`](references/lark-calendar-list-attendees.md) | 列出日程的参与人和会议室(支持按 `--type` 过滤:user / resource / chat / third_party) |

### `+get` — 单日程详情

通过 `calendar_id` + `event_id` 获取**单个日程**详情。

```bash
# calendar_id不传,默认primary
lark-cli calendar +get --calendar-id <calendar_id> --event-id <event_id>
```

日程描述统一使用 `description` 一个字段,按 **Markdown** 富文本处理。读取日程时 `description` 返回 Markdown 富文本(仅有纯文本描述时返回该纯文本);创建/更新日程时也通过 `--description` 传入 Markdown。

> `+get` 返回不含参会人和会议室。需要参与人视角(用户 / 会议室 / 群 / 三方邮箱)请调用 [`+list-attendees`](references/lark-calendar-list-attendees.md)。

### `+search-event` — 按关键词、时间范围和参会人搜索日程

仅返回基础字段(`event_id`/`summary`/`start`/`end` 等),需要详情请走 `+get`。

```bash
# query 按关键词 可选
# start/end 按时间范围(ISO 8601 或 YYYY-MM-DD)可选
# attendee-ids 按参会人(自动识别 ou_ 用户 / oc_ 群聊 / omm_ 会议室前缀)可选
# page-token 分页游标,用于继续翻页 可选
# page-size 每页数量,默认 30 可选
lark-cli calendar +search-event --query "周会" --start 2026-04-20 --end 2026-04-27 --attendee-ids "ou_user1,oc_chat1,omm_room1" --page-token <page_token> --page-size 30
```

`--attendee-ids` 的多值语义:**同类型内为 OR(并集)**——只要日程命中列表中的任意一个同类型 ID,就会返回。

- `--attendee-ids "ou_A,ou_B"` = A **或** B 参加的日程(**不是** A 和 B 都参加的)。

### `+delete` — 删除日程

```bash
# calendar_id不传,默认primary
lark-cli calendar +delete --calendar-id <calendar_id> --event-id <event_id> --notify=true
```

### `+agenda` — 查看近期日程安排

默认查询当天。结果应整理为按日期分组、按开始时间升序的易读时间线。

```bash
# start/end 时间范围(ISO 8601 / YYYY-MM-DD / Unix 秒),均可选;默认当天
# calendar-id 日历 ID(默认primary)可选
lark-cli calendar +agenda --start 2026-03-10 --end 2026-03-17 --calendar-id <calendar_id>
```

注意:
- 已取消的日程自动过滤;无日程时直接告知"日程清空"。
- 时间范围超过 40 天会自动拆分查询并合并结果。

### `+freebusy` — 查询主日历忙闲时段 / 事件 / 公共空闲

`+freebusy` 一个入口承担四种视角:几何计算类(`busy` / `free` / `common_free`)走自动合并;事件维度类(`raw_busy`)保留每条上游日程 + `rsvp_status`。

```bash
# start/end 时间范围(ISO 8601 / YYYY-MM-DD / Unix 秒),均可选;默认当天
# user-id 目标用户 open_id,可重复或用逗号分隔;默认当前登录用户,bot 身份必须显式传至少一个
# type 视角四选一(默认 busy):
#   busy         每个 user 合并后的忙碌区间(找空档、看忙碌时段)
#   raw_busy     每个 user 的原始日程块 + rsvp_status(数会议、看每个会的 rsvp)
#   free         每个 user 在时间窗内的空闲区间(可带 --min-duration 过滤)
#   common_free  所有 user 的共同空闲区间(可带 --min-duration 过滤)
# min-duration 仅对 free / common_free 生效;Go duration 格式,例如 30m、1h、90m

# 查询忙碌时间段(去重并合并相邻/重叠段)
lark-cli calendar +freebusy --start 2026-03-11 --end 2026-03-11 --user-id ou_a,ou_b --type busy

# 看别人有几个会、每个会的起止 + rsvp(不合并相邻/重叠段,带rsvp状态)
lark-cli calendar +freebusy --start 2026-03-11 --end 2026-03-11 --user-id ou_a,ou_b --type raw_busy

# 查询用户空闲时间段
lark-cli calendar +freebusy --start 2026-03-11 --end 2026-03-11 --user-id ou_a,ou_b --type free

# 多人公共空闲时间段(推荐替代手工合并)
lark-cli calendar +freebusy --start 2026-03-11T09:00:00+08:00 --end 2026-03-11T18:00:00+08:00 --user-id ou_a,ou_b --type common_free --min-duration 30m
```

用法提示:
- **`+freebusy` 只适用于查询忙碌/空闲时间段这一事实**。如果目标是"给会议**推荐**一个合适的时间段"(单人或多人),必须优先使用 [`+suggestion`](references/lark-calendar-suggestion.md)——它会综合**工作时间段、忙碌时间段、休息时间段**来推荐,`+freebusy` 只回答"哪些区间空着",不判断该区间是否适合排会。
- **多人公共空闲**:只想拿"哪些区间共同没被占"→ `--type common_free [--min-duration <dur>]`;想拿"推荐的会议时间段"→ 走 `+suggestion`。

## 前置条件路由

> **先判断是否重复性日程**:若操作对象是重复性日程,必须先读 [重复性日程操作规范](references/lark-calendar-recurring.md),并在用户未明确范围时先确认「仅此次/全部/此次及后续」(不要默认仅此次),再按下表进入具体操作流程。

| 场景 | 前置要求 |
|------|----------|
| 预约日程/会议、调整时间、查会议室 | 先读 [lark-calendar-schedule-meeting.md](references/lark-calendar-schedule-meeting.md) |
| 仅编辑字段(标题/描述)或增删参会人 | 先定位 `event_id`,再读 [lark-calendar-update.md](references/lark-calendar-update.md) |
| 调用任何 Shortcut | 先读其对应 reference 文档 |

## 写操作反馈

创建、更新、删除、RSVP 等写操作完成后,直接基于命令返回结果反馈用户;不要为了“确认是否生效”主动发起二次查询。只有用户明确要求复查,或命令返回信息不足以回答用户问题时,才需要再查询。

## 核心概念

- **日程实例(Instance)**:重复性日程展开后的具体时间实例。「仅此次」操作时使用具体实例的 `event_id`;「全部」或「此次及后续」操作时需对原重复性日程操作(使用原日程 `event_id`),并按需处理例外。
- **重复性日程例外(Exception)**:对重复性日程某次实例做过「仅此次」编辑后产生的独立日程(拥有独立 `event_id`)。删除/更新「全部」时必须同时处理例外,否则例外会残留。
- **全天日程(All-day Event)**:只按日期占用、没有具体起止时刻的
03

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
SKILL.md:155
- 日程分享链接:`https://<domain>/calendar/share?token=<token>`,指向日程本身,用于分享日程详情。**分享日程给某个人、某个群或粘贴到文档中,需要的都是这个日程分享链接(通过 `calendar events share_info` 获取),不是 applink**;禁止自己拼接 applink 或用 applink 代替。
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-07 · audit v0.4.1 · source sha 91a26abd3925full audit observations/trust-audit/skill/larksuite__lark-calendar.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-0791a26abd3925BLOCKD69first audit
05

Questions

What does the Lark Calendar skill do?

The official Lark/飞书 CLI tool, maintained by the larksuite team — built for humans and AI Agents. Covers core business domains including Messenger, Docs, Base, Sheets, Calendar, Mail, Tasks, Meetings, and more, with 200+ commands and 20+ AI Agent Skills.

Is Lark Calendar safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What can Lark Calendar access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (91a26abd3925), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement