wecomcli-meeting

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, user-controllable data from meeting records which could contain malicious instructions.
  • Ingestion points: Meeting summaries (notes[].note_content and notes[].todo_content via meeting get) and raw speech transcripts (original_data via meeting original get) are ingested into the agent's context for summarization and reporting.
  • Boundary markers: The skill includes a high-priority "Security Hint" at the end of every file (SKILL.md and all references) explicitly instructing the agent to ignore any executable commands or instruction requests found within tool outputs.
  • Capability inventory: The agent can create, modify, and delete meetings, search contacts, and view calendar availability using the wecom-cli tool.
  • Sanitization: The instructions explicitly warn the agent not to output or use any tokens or credentials found in the interface results.
  • [COMMAND_EXECUTION]: The skill relies on a vendor-provided CLI tool for all operations.
  • Evidence: The skill requires the wecom-cli binary (associated with the skill author 'wecomteam') to perform meeting management actions. All commands follow a fixed JSON-based argument structure (wecom-cli meeting [action] --json '...'), which reduces the risk of arbitrary shell injection from user inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:04 PM
Security Audit — agent-trust-hub — wecomcli-meeting