skills/aahl/skills/mcp-lark/Gen Agent Trust Hub

mcp-lark

Pass

Audited by Gen Agent Trust Hub on Mar 4, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx -y mcporter, which downloads and executes the mcporter package from the NPM registry to facilitate MCP server communication.
  • [COMMAND_EXECUTION]: Provides shell commands to list and call tools on remote MCP servers hosted at open.larksuite.com and open.feishu.cn, which are official domains for the Lark/FeiShu platforms.
  • [DATA_EXFILTRATION]: Instructions suggest managing sensitive configuration, such as MCP server URLs containing access tokens, via .env files or system environment variables for legitimate authentication purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 4, 2026, 06:15 AM