bitable
Warn
Audited by Socket on Mar 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the functional scope is narrowly aligned with readonly Bitable access, but the required `lark` CLI is not provenance-verified and the documented command/auth syntax appears inconsistent with the official Lark MCP tooling cited in the evidence. Main risk is supply-chain trust in an unverifiable local binary rather than overt malicious behavior or clear credential exfiltration.
Confidence: 86%Severity: 72%
Audit Metadata