wecom-unified

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install the @wecom/cli package from the npm registry using the command npm install -g @wecom/cli@0.1.8 to enable its core functionality.
  • [COMMAND_EXECUTION]: The suite utilizes the Bash tool to execute wecom-cli commands across various business domains, including contacts, messaging, and document management. It also recommends using system tools like curl or fetch for certain integration tasks.
  • [DATA_EXFILTRATION]: The skill defines a fallback mechanism for smartsheet operations that permits sending data to external Webhook URLs provided by the user during the session. While documented for interoperability, this enables a network communication path to arbitrary external endpoints.
  • [PROMPT_INJECTION]: The skill processes untrusted content from the WeCom platform, creating a surface for indirect prompt injection.
  • Ingestion points: External data enters the agent context via chat message retrieval (references/wecom-msg-get-message.md), document content fetching (references/wecom-doc-get-doc-content.md), and smartsheet record queries (references/wecom-doc-smartsheet-get-records.md).
  • Boundary markers: Absent. The instructions do not define specific delimiters or instructions to treat data from these sources as untrusted content.
  • Capability inventory: The agent has access to the Bash tool, allowing for the execution of CLI tools and network operations.
  • Sanitization: Absent. There is no mention of filtering, validation, or escaping logic applied to the data retrieved from WeCom before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — wecom-unified