Lark Workflow
Security checks across malware telemetry and agentic risk
Overview
The bundle is an instruction-only collection of Lark/Feishu CLI workflow SKILL.md files that are coherent with their stated purpose; no unexpected credentials, installers, or hidden endpoints were found, though there are a few minor metadata/instruction notes to review before installing.
This bundle appears to be what it claims: a set of Lark/Feishu CLI workflow definitions expressed as SKILL.md files. Before installing or running any recommended npx/npm commands: 1) verify the upstream repository/package (the package.json points to https://github.com/woodfantasy/lark-workflow) and review the source there; 2) avoid running broad "--recommend" auth unless you trust the environment—grant only the per-skill scopes you need; 3) be aware that the README suggests using npx to install packages, which will execute code downloaded from the network—inspect that code before running if possible; 4) rely on the documented user-confirmation gates for write operations, and do not skip those; and 5) note the registry metadata mismatch about required binaries (registry lists none while the bundle expects lark-cli) — the practical requirement is lark-cli, which is appropriate for these workflows.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
VirusTotal engine telemetry is currently stale for this artifact.
