dingtalk-aisearch

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses the dws command-line tool, which is an internal or vendor-specific utility from the 'dingtalk-real-ai' ecosystem. This is consistent with the skill's purpose for semantic search and content positioning within DingTalk.
  • [SAFE]: No hardcoded credentials or sensitive file paths (like .ssh or .aws) were found. The skill operates on organizational data (names, user IDs, node IDs) obtained through structured search results.
  • [SAFE]: There are no remote code execution patterns or external downloads from untrusted sources. All operations are local calls to the defined dws tool.
  • [SAFE]: The instructions contain clear boundary management (Golden Routes) to prevent unnecessary execution or tool switching, which reduces the risk of unintended behavior or resource abuse.
  • [SAFE]: No obfuscation (Base64, zero-width characters, etc.) was found in the text or instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:35 AM
Security Audit — agent-trust-hub — dingtalk-aisearch