lark-skill-maker
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The purpose is coherent with Feishu/Lark automation, and the API destinations appear consistent with official OpenAPI use. However, the skill’s core dependency is an unverified `lark-cli` binary that also handles authentication, creating a high trust and credential-forwarding risk disproportionate to the documentation provided.
Confidence: 84%Severity: 84%
Audit Metadata