dingtalk-contact

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a Python script scripts/contact_dept_members.py that facilitates department member lookups by executing the local dws CLI tool. The script uses subprocess.run with a list of arguments and no shell, which is a secure method for executing system commands. \n- [SAFE]: The skill provides access to sensitive organizational data such as employee profiles, rosters, and contract information. This access is consistent with its primary function as an administrative contact management tool for DingTalk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 07:07 PM
Security Audit — agent-trust-hub — dingtalk-contact