lark-contact

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent with querying contact and org-directory data, and there is no direct sign of exfiltration or unrelated capability in this fragment. However, the skill depends on an external `lark-cli` binary whose provenance, install source, and credential handling are not shown here, and critical auth behavior is deferred to another file not provided. That missing trust and data-flow context keeps the risk above benign, but there is not enough evidence in this fragment alone to call it malicious.

Confidence: 77%Severity: 52%
Audit Metadata
Analyzed At
Mar 28, 2026, 02:45 AM
Package URL
pkg:socket/skills-sh/larksuite%2Fcli%2Flark-contact%2F@5641d5a51711eb3d2d48f01be2e0e2c2ddbcbc7f