wecomcli-manage-smartsheet-data
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs all operations by calling the wecom-cli binary. This tool is used to execute commands for querying, adding, updating, and deleting records in WeCom smartsheets.
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it retrieves data from external sources. Ingestion points: Document records are read via the smartsheet_get_records tool defined in SKILL.md and references/api-get-records.md. Boundary markers: The instructions do not define delimiters or ignore-instruction warnings for the ingested data. Capability inventory: The skill has the ability to write to and delete records from WeCom documents via wecom-cli. Sanitization: No sanitization or validation logic is present for the data retrieved from external sheets.
Audit Metadata