Back to skill

Security audit

Lark CLI Dev Hub Drive

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Lark/Feishu Drive workflow guide that relies on the user-run lark-cli tool and does not include executable code or hidden behavior.

Install only if you already intend to use lark-cli with your Lark/Feishu account. Review commands before running them, especially export, upload, sync, permissions, and artifact writeback operations, because they can read or change Drive content using your authenticated account.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.