wecomcli-disk
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
wecom-clibinary to perform administrative tasks such as listing, searching, uploading, and downloading files from a cloud drive. This is the core functionality of the skill and uses a vendor-specific tool. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes data from an external source (WeCom Disk) that may be controlled by third parties.
- Ingestion points: The
wecom-cli disk files downloadcommand returns the content of files (file_content) to the agent context. Additionally, thesearchandlistcommands return file names and metadata that could contain malicious instructions. - Boundary markers: The skill specifies how to format output for the user (using markdown lists) but does not provide specific delimiters or instructions for the agent to ignore or sanitize commands embedded within the data it reads.
- Capability inventory: The skill has the capability to read local files (via
upload), write files to the local system (viadownload), and perform network requests to the WeCom API via the CLI tool. - Sanitization: There is no explicit sanitization or validation of the content retrieved from the cloud drive before it is processed by the agent.
Audit Metadata