mcp-lark

Fail

Audited by Runlayer on Mar 5, 2026

Risk Level: HIGH
Scan Summary
Max Score
91%
Files
2
Flagged
2
Chunks
5
Flagged Files (2)
mcp-lark/SKILL.mdHIGH
90.9%

Malicious tool definition detected

```shell # Configure multiple MCP service URLs and usage scenarios in environment variables LARK_MCP_SERVERS=' open.larksuite.com/mcp/stream/xxx:Chats and Mails;

mcp-lark/references/message_create.mdLOW
70.4%

Tool passed security scan

Malicious tool definition detected

|none | 75235e0c-4f92-430a-a99b-8446610223cg | **Message-sending Request Body Example** ```json { "receive_id": "oc_820faa21d7ed275b53d1727a0feaa917", "content": "{\"file_key\":\"file_v2_xxx\"}", "msg_type": "file" } ``` ### Sticker Currently, only emojis received by the bot can be sent.

Audit Metadata
Max File Score
91%
Classification
KNOWN_SERVER_ALL_UNKNOWN
Files Scanned
2
Files Flagged
2
Chunks Analyzed
5
Analyzed
Mar 5, 2026, 07:02 AM
Security Audit — runlayer — mcp-lark