dingtalk-dev

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill operates primarily by executing a variety of subcommands under the dws dev namespace to manage DingTalk application containers, including their credentials, permissions, and deployment versions.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the official Claude Code developer tool from Anthropic's public npm registry when setting up local robot debugging. This dependency is sourced from a well-known technology provider and is necessary for the skill's local agent connectivity functionality.
  • [CREDENTIALS_UNSAFE]: Although the skill handles sensitive application credentials such as appSecret and clientSecret, it contains proactive instructions for the agent to redact these values from its output. This design adheres to security best practices for protecting sensitive secrets during user interactions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 11:20 AM
Security Audit — agent-trust-hub — dingtalk-dev