lark-contact

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent with querying contact and org-directory data, and there is no direct sign of exfiltration or unrelated capability in this fragment. However, the skill depends on an external `lark-cli` binary whose provenance, install source, and credential handling are not shown here, and critical auth behavior is deferred to another file not provided. That missing trust and data-flow context keeps the risk above benign, but there is not enough evidence in this fragment alone to call it malicious.

Confidence: 77%Severity: 52%
Audit Metadata
Analyzed At
Apr 13, 2026, 09:53 AM
Package URL
pkg:socket/skills-sh/liangdabiao%2Flark-workflow-feishu-cli%2Flark-contact%2F@5641d5a51711eb3d2d48f01be2e0e2c2ddbcbc7f