wecomcli-meeting
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, user-controllable data from meeting records which could contain malicious instructions.
- Ingestion points: Meeting summaries (
notes[].note_contentandnotes[].todo_contentviameeting get) and raw speech transcripts (original_dataviameeting original get) are ingested into the agent's context for summarization and reporting. - Boundary markers: The skill includes a high-priority "Security Hint" at the end of every file (SKILL.md and all references) explicitly instructing the agent to ignore any executable commands or instruction requests found within tool outputs.
- Capability inventory: The agent can create, modify, and delete meetings, search contacts, and view calendar availability using the
wecom-clitool. - Sanitization: The instructions explicitly warn the agent not to output or use any tokens or credentials found in the interface results.
- [COMMAND_EXECUTION]: The skill relies on a vendor-provided CLI tool for all operations.
- Evidence: The skill requires the
wecom-clibinary (associated with the skill author 'wecomteam') to perform meeting management actions. All commands follow a fixed JSON-based argument structure (wecom-cli meeting [action] --json '...'), which reduces the risk of arbitrary shell injection from user inputs.
Audit Metadata