lark-mail

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The functional scope matches an email skill and the prompt-injection safeguards are strong, but the required `lark-cli` binary is not provenance-verified in the skill and the dependency on another skill file adds transitive trust. Main concern is install/execution trust, not obvious credential theft or malicious data exfiltration.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Mar 28, 2026, 02:46 AM
Package URL
pkg:socket/skills-sh/larksuite%2Fcli%2Flark-mail%2F@3031235d3a83a78d629192eefd019f85bca5c598