wecomcli-calendar
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it ingests untrusted data from tool outputs and performs actions based on that data.
- Ingestion points: Data enters the agent's context through outputs from
schedules list,schedules search,schedules get,rooms search,buildings list, andfree listcommands across all reference files. - Boundary markers: The instructions do not explicitly mandate the use of delimiters or "ignore embedded instructions" warnings for the data retrieved from the CLI tool.
- Capability inventory: The skill has the capability to write to the enterprise calendar system via
schedules create,schedules update, andschedules cancelcommands. - Sanitization: The skill implements sanitization by requiring the resolution of user-provided names into specific, validated
useridformats (woprefix) via a separate contact skill and enforces strict time and ID format validation.
Audit Metadata