lark-mail
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The functional scope matches an email skill and the prompt-injection safeguards are strong, but the required `lark-cli` binary is not provenance-verified in the skill and the dependency on another skill file adds transitive trust. Main concern is install/execution trust, not obvious credential theft or malicious data exfiltration.
Confidence: 88%Severity: 72%
Audit Metadata