lark-router

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and documented behavior are coherent for Lark auth routing, and `lark-cli` appears to be an official same-org tool. The main issue is that the skill depends on `larc`, whose ownership and release provenance were not verified; under the required scoring rules, a required unverifiable CLI makes the skill high security risk even without direct evidence of exfiltration.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
May 1, 2026, 10:37 AM
Package URL
pkg:socket/skills-sh/ShunsukeHayashi%2Flark-harness%2Flark-router%2F@0e263dac14660e716fb7595ff7554d772ae487bd