dingtalk-aisearch
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses the
dwscommand-line tool, which is an internal or vendor-specific utility from the 'dingtalk-real-ai' ecosystem. This is consistent with the skill's purpose for semantic search and content positioning within DingTalk. - [SAFE]: No hardcoded credentials or sensitive file paths (like .ssh or .aws) were found. The skill operates on organizational data (names, user IDs, node IDs) obtained through structured search results.
- [SAFE]: There are no remote code execution patterns or external downloads from untrusted sources. All operations are local calls to the defined
dwstool. - [SAFE]: The instructions contain clear boundary management (Golden Routes) to prevent unnecessary execution or tool switching, which reduces the risk of unintended behavior or resource abuse.
- [SAFE]: No obfuscation (Base64, zero-width characters, etc.) was found in the text or instructions.
Audit Metadata