lark-event
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The purpose and capabilities are mostly aligned, but the skill's core function depends on a non-official third-party CLI (`lark-cli`) and implicitly forwards Lark authentication to it via shared auth instructions. With no official install path or direct endpoint verification in the snippet, the main risk is supply-chain and credential exposure rather than confirmed malicious behavior.
Confidence: 83%Severity: 76%
Audit Metadata