wps

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the 'kdocs-cli' tool from the official WPS Content Delivery Network.
  • The setup scripts (setup.sh, setup.ps1, setup.cjs) download platform-specific binaries from https://wpsai.wpscdn.cn/skillhub/pro for installation.
  • [REMOTE_CODE_EXECUTION]: Implements a self-update mechanism that downloads and extracts code archives.
  • Instructions in SKILL.md direct the agent to download a ZIP file and replace the skill content when the check_skill_update command indicates a new version is available.
  • [COMMAND_EXECUTION]: Extensive use of shell commands to interact with user documents.
  • The skill uses kdocs-cli to perform high-privilege operations on cloud storage, including file deletion and sharing, but mandates user confirmation and credential safety practices.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 08:54 AM
Security Audit — agent-trust-hub — wps