wecom-smartsheet-schema
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface
- Ingestion points: User-provided document IDs, URLs, and titles are processed in SKILL.md.
- Boundary markers: No explicit delimiters are used to separate user data from instructions.
- Capability inventory: The skill can perform irreversible delete operations on sheets and fields.
- Sanitization: No sanitization process is described for the tool inputs.
- [COMMAND_EXECUTION]: Tool Invocation
- The skill executes the wecom_mcp command-line tool to perform document management tasks, which involves handling user-supplied strings within a CLI environment.
Audit Metadata