dingtalk-ai-table

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local utility scripts/dt_helper.sh for configuration and token management. It also utilizes temporary bash scripts in /tmp for executing table-related API calls safely.- [EXTERNAL_DOWNLOADS]: Communicates with official DingTalk endpoints (api.dingtalk.com and oapi.dingtalk.com) to manage access tokens and table records.- [DYNAMIC_EXECUTION]: Instructions direct the agent to generate and execute shell scripts in /tmp to ensure the integrity of multi-line commands and variable handling.- [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for processing data from external DingTalk tables. Ingestion points: Record, field, and sheet data retrieved from Notable APIs (documented in references/api.md). Boundary markers: None explicitly defined for external API data. Capability inventory: Network operations (curl), file writes (~/.dingtalk-skills/config), and shell execution. Sanitization: Data is primarily used for structured table operations without specific sanitization routines.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:56 AM
Security Audit — agent-trust-hub — dingtalk-ai-table