lark-openapi-explorer

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent and the doc/data flow targets official Feishu/Lark domains, but the skill’s required `lark-cli` binary is not verified as an official publisher-controlled tool in the provided evidence. Because that binary likely handles authenticated API calls, the main risk is supply-chain plus credential forwarding rather than obvious malware.

Confidence: 84%Severity: 84%
Audit Metadata
Analyzed At
Mar 28, 2026, 02:45 AM
Package URL
pkg:socket/skills-sh/larksuite%2Fcli%2Flark-openapi-explorer%2F@b403a77f10cf342a01792241a3e77231842c438c