The skill lacks documentation for its core functions and introduces security risks by processing potentially malicious external content without adequate validation or defined usage terms.
npx skills add https://github.com/larksuite/cliThe skill supports downloading and processing external message content and files, which could contain malicious payloads that the agent might execute or follow if the content is treated as instructions.
Opt-in resource auto-download (`--download-resources`)
SKILL.md links to "references/lark-im-chat-create.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[`+chat-create`](references/lark-im-chat-create.md)
SKILL.md links to "references/lark-im-chat-list.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[`+chat-list`](references/lark-im-chat-list.md)
SKILL.md links to "references/lark-im-chat-messages-list.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[`+chat-messages-list`](references/lark-im-chat-messages-list.md)
SKILL.md links to "references/lark-im-message-enrichment.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[`references/lark-im-message-enrichment.md`](references/lark-im-message-enrichment.md)
SKILL.md links to "references/lark-im-messages-resources-download.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[`+messages-resources-download`](references/lark-im-messages-resources-download.md)
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/larksuite/cli/lark-im)<a href="https://mondoo.com/ai-agent-security/skills/github/larksuite/cli/lark-im"><img src="https://mondoo.com/ai-agent-security/api/badge/github/larksuite/cli/lark-im.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/larksuite/cli/lark-im.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.