lark-im

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s capabilities align with its stated Lark IM purpose, and its data flows appear aimed at official Lark messaging operations. The main risk is trust in the required third-party lark-cli binary, which handles Lark credentials and actions without install verification details in the skill; this is a significant supply-chain and credential-forwarding concern, but not confirmed malicious behavior.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 28, 2026, 02:46 AM
Package URL
pkg:socket/skills-sh/larksuite%2Fcli%2Flark-im%2F@2dd9d6e8b35d2b88f26de1b864677fda9f298c3b