dws-shared

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructional content on how to interact with the 'dws' binary. It includes built-in security guardrails such as requiring user confirmation for write, delete, or organization-switching operations.
  • [DATA_EXPOSURE]: The skill discusses credential management (authentication and keychain migration), but these actions are local to the 'dws' CLI tool and do not involve exfiltration to external third-party domains.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute 'dws' commands. These commands are part of the intended functionality for managing DingTalk resources and do not represent arbitrary command injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface where the agent processes command schemas and documentation results. While this is an ingestion point for external data, the skill provides specific rules to prevent the agent from being misled by conflicting schemas or help outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 11:20 AM
Security Audit — agent-trust-hub — dws-shared