Atlas / MCP servers / larksuite / Lark OpenAPI

Lark OpenAPICAUTION

mcp/larksuite/lark-openapi

飞书/Lark官方 OpenAPI MCP

Verdict
CAUTION
Grade
C
Trust score
72 /100
Exposed tools
17 15r · 2w · 0d
Transport
sse · stdio · streamable-http
License
MIT
Stars
839
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@larksuiteoapi/lark-mcp) [](https://www.npmjs.com/package/@larksuiteoapi/lark-mcp) [](https://nodejs.org/)

English | 中文

Developer Documentation Retrieval MCP

Official Document

Trouble Shooting

⚠️ Beta Version Notice: This tool is currently in Beta stage. Features and APIs may change, so please stay updated with version releases.

This is the Feishu/Lark official OpenAPI MCP (Model Context Protocol) tool designed to help users quickly connect to the Feishu/Lark platform and enable efficient collaboration between AI Agents and Feishu/Lark. The tool encapsulates Feishu/Lark Open Platform API interfaces as MCP tools, allowing AI assistants to directly call these interfaces and implement various automation scenarios such as document processing, conversation management, calendar scheduling, and more.

Preparation

Creating a Feishu/Lark Application

Before using the lark-mcp tool, you need to create a Feishu/Lark application:

  1. Visit the Feishu Open Platform or Lark Open Platform and log in
  2. Click "Console" and create a new application
  3. Obtain the App ID and App Secret, which will be used for API authentication
  4. Add the necessary permissions for your application based on your usage scenario
  5. If you need to call APIs as a user, set the OAuth 2.0 redirect URL to http://localhost:3000/callback

For detailed application creation and configuration guidelines, please refer to the [Feishu Open Plat

Read from source at commit dc92d0e5a0c5OBSERVED · 2026-09-27
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add lark-mcp --env APP_SECRET=${APP_SECRET} --env LARK_TOKEN_MODE=${LARK_TOKEN_MODE} --env USER_ACCESS_TOKEN=${USER_ACCESS_TOKEN} -- npx -y @larksuiteoapi/[email protected]
claude-desktop
{
  "mcpServers": {
    "lark-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@larksuiteoapi/[email protected]"
      ],
      "env": {
        "APP_SECRET": "${APP_SECRET}",
        "LARK_TOKEN_MODE": "${LARK_TOKEN_MODE}",
        "USER_ACCESS_TOKEN": "${USER_ACCESS_TOKEN}"
      }
    }
  }
}
03

Exposed tools (17)

15 read · 2 write · 0 destructive.

ToolRiskDescription
RecallToolreadRecallTool description
async-toolreadAsync tool
custom.handler.toolread自定义处理程序工具
docx.v1.document.rawContentread获取文档内容
im.v1.chat.createwrite创建群
im.v1.message.createwrite发送消息
im.v1.message.nonFunctionread测试非函数路径
image-toolreadImage tool
multi-toolreadMulti tool
openplatform_developer_document_recallreadRecall for relevant documents in all of the Feishu/Lark Open Platform Developer Documents based on user input.
refined-toolreadRefined tool
string-toolreadString tool
test-recall-toolreadA test recall tool
test.toolread测试工具
text-toolreadText tool
validation-toolreadValidation tool
wiki.v1.node.searchread搜索知识库节点
04

Trust audit

CAUTIONgrade C · trust 72/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth/handler/handler.ts:108
logger.error(`[LarkAuthHandler] refreshToken: No local access token found`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth/handler/handler.ts:112
logger.error(`[LarkAuthHandler] refreshToken: No refresh token found`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth/handler/handler.ts:122
logger.info(`[LarkAuthHandler] refreshToken: Successfully refreshed token`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth/handler/handler.ts:130
logger.error(`[LarkAuthHandler] reAuthorize: Invalid access token, please reconnect the mcp server`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth/handler/handler.ts:136
logger.error(`[LarkAuthHandler] reAuthorize: Invalid access token, please reconnect the mcp server`);
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/mcp-tool/tools/en/gen-tools/zod/approval_v4.ts:538
"Key:Value of the text. The key needs to start with @i18n@ and the value must be passed in according to the requirements of each parameter.**Description**: This field is mainly used for internationali
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/mcp-tool/tools/en/gen-tools/zod/approval_v4.ts:559
'The department ID type in this call. For a detailed description of department IDs, see [Department ID Description]. Options:department_id(DepartmentId Supports user-defined department ID. When custom
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/mcp-tool/tools/en/gen-tools/zod/approval_v4.ts:651
'Approval instance extension parameter, JSON format, needs to be compressed and escaped into a string when passing the value. The document number is realized by passing the business_key parameter.**No
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/mcp-tool/tools/en/gen-tools/zod/base_v2.ts:104
'A readable view collection. This is only meaningful when view_perm is 1. If it is not set, all views are readable. If it is set, it means that only views in the collection are readable, and views out
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/mcp-tool/tools/en/gen-tools/zod/base_v2.ts:130
'base role`base_complex_edit`: Set whether you can create copies, download, and print multidimensional tables`copy`: Set whether you can copy the contents of multidimensional tablesThe parameter type 
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/auth/handler/handler-local.ts:7
import { logger } from '../../utils/logger';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/auth/handler/handler.ts:7
import { logger } from '../../utils/logger';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/auth/provider/oauth.ts:9
import { commonHttpInstance } from '../../utils/http-instance';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/auth/provider/oauth.ts:10
import { logger } from '../../utils/logger';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/auth/provider/oidc.ts:11
import { commonHttpInstance } from '../../utils/http-instance';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@larksuiteoapi/node-sdk, @modelcontextprotocol/sdk, axios, commander, dotenv, env-paths, express, keytar
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/reference/cli/cli.md:77
| `--user-access-token` | `-u` | User access token for calling APIs as a user | `-u u-xxxx` |
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/reference/tool-presets/tools-en.md:768
| drive.v1.permissionPublicPassword.create | [Open password](https://open.feishu.cn/document/uAjLw4CM/ukTMukTMukTM/reference/drive-v1/permission-public-password/create) | This interface is used to ena
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/usage/configuration/configuration.md:257
> 💡 **Tip**: The system will automatically read `APP_ID` and `APP_SECRET` environment variables, no need to specify them again in args.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/usage/configuration/configuration.md:302
| `USER_ACCESS_TOKEN` | `-u, --user-access-token` | User access token | `u-zzzzz` |
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/reference/tool-presets/tools-en.md:32
| admin.v1.password.reset | [Reset user enterprise email password](https://open.feishu.cn/document/uAjLw4CM/ukTMukTMukTM/reference/admin-v1/password/reset) | Admin-Login password management-Reset user
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/reference/tool-presets/tools-en.md:37
| aily.v1.ailySessionAilyMessage.create | [Send aily message](https://open.feishu.cn/document/uAjLw4CM/ukTMukTMukTM/aily-v1/aily_session-aily_message/create) | The API is used to send a message to a F
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/reference/tool-presets/tools-en.md:40
| aily.v1.ailySession.create | [Create session](https://open.feishu.cn/document/uAjLw4CM/ukTMukTMukTM/aily-v1/aily_session/create) | This API is used to create a session with a Feishu smart partner ap
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/reference/tool-presets/tools-en.md:843
| hire.v1.ecoExam.loginInfo | [Post exam login info](https://open.feishu.cn/document/ukTMukTMukTM/uMzM1YjLzMTN24yMzUjN/hire-v1/eco_exam/login_info) | The written test service provider of Feishu Hire, 
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-09-27 · audit v0.4.1 · source sha dc92d0e5a0c5full audit observations/trust-audit/mcp-server/larksuite__lark-openapi.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-27dc92d0e5a0c5CAUTIONC72first audit
06

Questions

What is the Lark OpenAPI MCP server?

飞书/Lark官方 OpenAPI MCP

What tools does Lark OpenAPI expose?

17 in total: 15 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Lark OpenAPI safe to connect to an agent?

With care. The audit graded it C (72/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Lark OpenAPI need?

It reads APP_SECRET, LARK_TOKEN_MODE and USER_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Lark OpenAPI run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @larksuiteoapi/lark-mcp at 0.5.1.

How current is this page?

The grade is for one exact copy of the source (dc92d0e5a0c5), read on 2026-09-27. The repository is watched and re-audited when it changes.

Advertisement