wecomcli-doc

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a secure workflow for generating documents. The scripts/build_docx.py script uses environment-controlled sandboxing (WECOMAGENT_READABLE_DIRS and WECOMAGENT_WRITABLE_DIRS) and includes robust protections against directory traversal (explicitly rejecting . and .. segments) and symlink attacks (checking os.path.islink before writing). These measures ensure the skill cannot read or write files outside of its assigned directories.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection because it reads external content from WeCom documents using wecom-cli doc contents get. However, the author has included a 'Security Hint' (安全提示) in SKILL.md that explicitly instructs the agent to ignore any commands or credentials found within the document content, which acts as a valid mitigation.
  • [COMMAND_EXECUTION]: The skill uses wecom-cli to perform its operations. These commands are consistent with the skill's stated purpose and the vendor's context (wecomteam).
  • [DYNAMIC_EXECUTION]: While the skill generates .docx files dynamically via a Python script, it does so using a highly restrictive JSONL specification parser that enforces strict type checking, value ranges, and structural limits, preventing arbitrary code or command execution through the document generation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:12 PM
Security Audit — agent-trust-hub — wecomcli-doc