lark-cli

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and installs the official @larksuite/cli package from the npm registry using npx. This is a standard procedure for installing official developer tools and originates from a well-known service.
  • [COMMAND_EXECUTION]: The skill executes lark-cli commands and npm/npx to manage the lifecycle of the Lark developer environment. These operations are limited to the intended scope of the skill and include safety measures like --dry-run support.
  • [DATA_EXFILTRATION]: There are no indicators of unauthorized data collection. The skill manages OAuth authentication URLs and setup tokens which are intended to be presented to the user for manual intervention in a browser.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 11:51 AM
Security Audit — agent-trust-hub — lark-cli