wecomcli-doc
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a secure workflow for generating documents. The
scripts/build_docx.pyscript uses environment-controlled sandboxing (WECOMAGENT_READABLE_DIRSandWECOMAGENT_WRITABLE_DIRS) and includes robust protections against directory traversal (explicitly rejecting.and..segments) and symlink attacks (checkingos.path.islinkbefore writing). These measures ensure the skill cannot read or write files outside of its assigned directories. - [INDIRECT_PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection because it reads external content from WeCom documents using
wecom-cli doc contents get. However, the author has included a 'Security Hint' (安全提示) inSKILL.mdthat explicitly instructs the agent to ignore any commands or credentials found within the document content, which acts as a valid mitigation. - [COMMAND_EXECUTION]: The skill uses
wecom-clito perform its operations. These commands are consistent with the skill's stated purpose and the vendor's context (wecomteam). - [DYNAMIC_EXECUTION]: While the skill generates
.docxfiles dynamically via a Python script, it does so using a highly restrictive JSONL specification parser that enforces strict type checking, value ranges, and structural limits, preventing arbitrary code or command execution through the document generation process.
Audit Metadata