wecom-unified
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to install the
@wecom/clipackage from the npm registry using the commandnpm install -g @wecom/cli@0.1.8to enable its core functionality. - [COMMAND_EXECUTION]: The suite utilizes the
Bashtool to executewecom-clicommands across various business domains, including contacts, messaging, and document management. It also recommends using system tools likecurlorfetchfor certain integration tasks. - [DATA_EXFILTRATION]: The skill defines a fallback mechanism for smartsheet operations that permits sending data to external Webhook URLs provided by the user during the session. While documented for interoperability, this enables a network communication path to arbitrary external endpoints.
- [PROMPT_INJECTION]: The skill processes untrusted content from the WeCom platform, creating a surface for indirect prompt injection.
- Ingestion points: External data enters the agent context via chat message retrieval (references/wecom-msg-get-message.md), document content fetching (references/wecom-doc-get-doc-content.md), and smartsheet record queries (references/wecom-doc-smartsheet-get-records.md).
- Boundary markers: Absent. The instructions do not define specific delimiters or instructions to treat data from these sources as untrusted content.
- Capability inventory: The agent has access to the
Bashtool, allowing for the execution of CLI tools and network operations. - Sanitization: Absent. There is no mention of filtering, validation, or escaping logic applied to the data retrieved from WeCom before it is processed by the agent.
Audit Metadata