lark-event

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The purpose and capabilities are mostly aligned, but the skill's core function depends on a non-official third-party CLI (`lark-cli`) and implicitly forwards Lark authentication to it via shared auth instructions. With no official install path or direct endpoint verification in the snippet, the main risk is supply-chain and credential exposure rather than confirmed malicious behavior.

Confidence: 83%Severity: 76%
Audit Metadata
Analyzed At
Mar 28, 2026, 02:45 AM
Package URL
pkg:socket/skills-sh/larksuite%2Fcli%2Flark-event%2F@e14505a7e33461645ce9f2302afda1d360fb484b