dingtalk-profile

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate functionality for managing vendor-specific DingTalk identities. No malicious patterns such as credential exfiltration, unauthorized network requests, or obfuscated code were detected.- [COMMAND_EXECUTION]: The skill relies on the 'dws' command-line utility to perform administrative tasks, including listing profiles, logging in/out, and switching the active organizational context. These commands are consistent with the skill's stated purpose.- [PROMPT_INJECTION]: The skill provides instructions for searching data across multiple organizations (chats, documents, contacts), which introduces a surface for indirect prompt injection from retrieved content. The skill mitigates this by instructing the agent to adhere to safety guardrails and seek user confirmation for non-read operations.
  • Ingestion points: Search results retrieved from DingTalk chats, documents, and wikis via the 'dws' binary (SKILL.md).
  • Boundary markers: None specified.
  • Capability inventory: Profile switching, authentication management, and data retrieval across organizations (SKILL.md).
  • Sanitization: No specific sanitization or content filtering is implemented for external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 11:21 AM
Security Audit — agent-trust-hub — dingtalk-profile