Lark

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Lark integration, but it gives an agent broad access to sensitive workplace data and destructive actions without enough safety guidance.

Review before installing. Use the narrowest Lark app scopes possible, avoid connecting an admin account unless required, and require explicit user confirmation before deleting content, changing permissions, removing people, approving or rejecting workflows, ending meetings, or reading and sharing transcripts or recordings.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill documents destructive actions like deleting messages without any requirement to confirm intent, describe consequences, or suggest guardrails. In an agent setting, this increases the chance of accidental or prompt-induced destructive changes to user data or communications.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill exposes broad capabilities to read messages, documents, calendars, contacts, meeting transcripts, recordings, approvals, and other potentially sensitive enterprise data, but it does not include privacy, consent, or least-privilege guidance. In an agent workflow, this can normalize bulk access to confidential business and personal information without adequate user awareness or restrictions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal