lark-cli-setup

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose largely matches installing the official Lark CLI, but the skill is not proportionate: it hardcodes a reusable App Secret, automatically installs a second skill bundle with 19 additional capabilities, and expands the agent into real-world messaging/document/mail actions. Official npm provenance lowers malware confidence, but plaintext credential exposure and transitive skill installation make the overall security posture high risk.

Confidence: 92%Severity: 81%
Audit Metadata
Analyzed At
Apr 13, 2026, 07:18 AM
Package URL
pkg:socket/skills-sh/horizon-continental%2Fhct-skills%2Flark-cli-setup%2F@9a4e4227f9175dae41ac27e10fa6c08bb9663f96