dingtalk-dev

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill defines a robust set of security guidelines, notably requiring the desensitization of sensitive application credentials (appSecret and clientSecret) in all agent outputs to prevent accidental exposure.
  • [SAFE]: All administrative operations involve a mandatory '--dry-run' phase followed by user confirmation ('--yes'), ensuring no unintended changes are made to the application state.
  • [SAFE]: The skill documentation and recipes for image uploading and token management target only the official DingTalk API domain (oapi.dingtalk.com).
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of official developer tools, such as the Claude Code CLI from the trusted '@anthropic-ai' NPM organization, to support local agent connections.
  • [SAFE]: The skill uses the 'dws' binary, which is explicitly declared as a required dependency in the skill metadata, adhering to standard platform requirements for local tool interaction.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 09:43 AM
Security Audit — agent-trust-hub — dingtalk-dev