lark-skill-maker

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The purpose is coherent with Feishu/Lark automation, and the API destinations appear consistent with official OpenAPI use. However, the skill’s core dependency is an unverified `lark-cli` binary that also handles authentication, creating a high trust and credential-forwarding risk disproportionate to the documentation provided.

Confidence: 84%Severity: 84%
Audit Metadata
Analyzed At
Mar 28, 2026, 02:45 AM
Package URL
pkg:socket/skills-sh/larksuite%2Fcli%2Flark-skill-maker%2F@f1f0673f26a0b5d2b6cf12454dd47253587f181e