larc-onboarding

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated onboarding purpose is mostly coherent, and official OpenClaw/Lark commands appear aligned, but the LARC runtime installation uses an unpinned `curl|bash` from a personal GitHub raw URL. That supply-chain risk is disproportionate for an onboarding skill handling tenant auth, so the skill is not clearly malicious but should not be treated as low-risk.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
May 1, 2026, 10:38 AM
Package URL
pkg:socket/skills-sh/ShunsukeHayashi%2Flark-harness%2Flarc-onboarding%2F@c09253f3a220daaa5bc57e4c55b4152a2c497111