wecomcli-disk

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the wecom-cli binary to perform administrative tasks such as listing, searching, uploading, and downloading files from a cloud drive. This is the core functionality of the skill and uses a vendor-specific tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes data from an external source (WeCom Disk) that may be controlled by third parties.
  • Ingestion points: The wecom-cli disk files download command returns the content of files (file_content) to the agent context. Additionally, the search and list commands return file names and metadata that could contain malicious instructions.
  • Boundary markers: The skill specifies how to format output for the user (using markdown lists) but does not provide specific delimiters or instructions for the agent to ignore or sanitize commands embedded within the data it reads.
  • Capability inventory: The skill has the capability to read local files (via upload), write files to the local system (via download), and perform network requests to the WeCom API via the CLI tool.
  • Sanitization: There is no explicit sanitization or validation of the content retrieved from the cloud drive before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 07:05 AM
Security Audit — agent-trust-hub — wecomcli-disk