wecomcli-calendar

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it ingests untrusted data from tool outputs and performs actions based on that data.
  • Ingestion points: Data enters the agent's context through outputs from schedules list, schedules search, schedules get, rooms search, buildings list, and free list commands across all reference files.
  • Boundary markers: The instructions do not explicitly mandate the use of delimiters or "ignore embedded instructions" warnings for the data retrieved from the CLI tool.
  • Capability inventory: The skill has the capability to write to the enterprise calendar system via schedules create, schedules update, and schedules cancel commands.
  • Sanitization: The skill implements sanitization by requiring the resolution of user-provided names into specific, validated userid formats (wo prefix) via a separate contact skill and enforces strict time and ID format validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 07:05 AM
Security Audit — agent-trust-hub — wecomcli-calendar