skills/getlark/skills/setup/Gen Agent Trust Hub

setup

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Installs the @getlark/cli global package using npm install -g. This is a vendor-supplied resource intended for the tool's core functionality.
  • [COMMAND_EXECUTION]: Modifies shell profile files such as ~/.zshrc and ~/.bashrc to append environment variable exports for persistence.
  • [CREDENTIALS_UNSAFE]: Persists the LARKCI_API_KEY in plain text within the user's shell configuration files, making it accessible to any process that can read those files.
  • [COMMAND_EXECUTION]: Suggests the use of sudo in the recovery steps to overcome potential file system permission issues during global package installation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 07:54 PM
Security Audit — agent-trust-hub — setup