Proactive cognitive AI assistant with Feishu/WeChat integration — learns user interests, pushes cross-domain insights, evolves skills, self-corrects. 40+ LLM providers, runs on cloud/desktop/Android.
LPM flags this version as an AI-agent control-surface risk. Installation automatically invokes npx to add all Lark CLI skills to the user's global AI-agent skills directory. This mutates a foreign/broad agent control surface without an explicit user action.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/control-ui/assets/index-B2vTvM2B.jsView on unpkg · L911Package source references dynamic require/import behavior.
dist/control-ui/assets/index-B2vTvM2B.jsView on unpkg · L912Source writes installer persistence such as shell profile or service configuration.
dist/update-cli-Cdj2DQ8v.jsView on unpkg · L36Package ships non-JavaScript build or shell helper files.
skills/video-frames/scripts/frame.shView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/extensions/diffs/assets/viewer-runtime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/launchd-Cm2E2m_1.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/clawhub-Br81or9N.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/schtasks-B69xcxhh.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/windows-spawn-zUnahlxC.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/anthropic-vertex-stream-Ce4FIZKv.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L1104Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/control-ui/assets/index-B2vTvM2B.jsView on unpkg · L911Package source references dynamic require/import behavior.
dist/control-ui/assets/index-B2vTvM2B.jsView on unpkg · L912Package ships non-JavaScript build or shell helper files.
skills/video-frames/scripts/frame.shView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/extensions/diffs/assets/viewer-runtime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/launchd-Cm2E2m_1.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/clawhub-Br81or9N.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/schtasks-B69xcxhh.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/windows-spawn-zUnahlxC.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/anthropic-vertex-stream-Ce4FIZKv.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/update-cli-Cdj2DQ8v.jsView on unpkg · L36