Security audit
Lark CLI Dev Hub Drive
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed Lark/Feishu Drive workflow guide that relies on the user-run lark-cli tool and does not include executable code or hidden behavior.
Install only if you already intend to use lark-cli with your Lark/Feishu account. Review commands before running them, especially export, upload, sync, permissions, and artifact writeback operations, because they can read or change Drive content using your authenticated account.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
VirusTotal findings are pending for this skill version.
Static analysis
No suspicious patterns detected.
