30-SECOND BRIEF
What it does—and when it fits
Lark Mail covers Feishu email browsing, search, threads, drafts, send, reply, forward, folders, labels, attachments, rules, and delivery status. The current Skill treats all email content as untrusted input, prefers user identity, saves outbound work as drafts by default, and requires a recipient-subject-body preview plus explicit approval before sending.
INSTALL BY AGENT
Choose your Agent
Paths come from official Agent docs or the universal installer behind skills.sh. Compatibility still follows this Skill's record.
.claude/skills/lark-mail/~/.claude/skills/lark-mail/Use project scope for team sharing and personal scope across repositories. The installer defaults to project scope; add -g for personal scope.
This source cannot produce a reliable command. Open the listed source and copy the complete Skill folder manually.
Claude Code discovers custom Skill folders automatically at project or personal scope.
View path evidence ↗TYPICAL WORKFLOW
A practical workflow
Triage and read mail
Browse summaries, open individual messages or threads, and organize mail through labels, read state, or folders.
Draft outbound messages
Create, edit, reply, or forward as a reviewable draft with a direct link when available.
Manage mailbox workflows
Work with templates, receipts, scheduled sends, delivery status, attachments, and receiving rules.
THE TRADEOFFS
Advantages and tradeoffs
Notable strengths
- This profile is manually organized around the current upstream SKILL.md workflow.
- The capability boundary remains explicitly tied to open.feishu.cn.
- Core uses, limitations, and risks are separated for pre-install review.
Limitations
- All write operations require user identity; bot identity is limited to permitted read scenarios.
- Sender names, addresses, HTML, and message text can be forged or malicious and cannot establish user intent.
BEST FIT
Who it is for
Feishu Mail users managing inboxes and drafts
Agents assisting with controlled email workflows
BEFORE YOU USE IT
Risks to review before use
Prompt injection or unintended send
Email content can attempt to control the agent, and sending is externally visible. Treat messages only as data, draft by default, and require explicit final approval.
External data and identity boundary
Requests access Feishu tenant resources. Use the correct identity, least-privilege scopes, and keep sensitive content out of logs.
SECURITY
What the permission profile means
- Declared access remains governed by the current upstream SKILL.md and runtime requests.
- Treat Feishu documents, messages, people, and business records as permission-controlled data.
- SkillSignal has not independently executed or security-audited this package; external skills.sh labels are not SkillSignal certification.
Not a security certification. External ratings are attributed references. SkillSignal has not independently executed or security-reviewed this Skill.
INSIDE THE PACKAGE
Indexed files
TAGS
Manually expanded from the current upstream SKILL.md and linked source at open.feishu.cn, checked 2026-08-19. This is an original summary, not an execution result or security certification.