wecomcli-sheet
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external spreadsheets that are considered untrusted sources, providing an attack surface for instructions hidden within cell data.
- Ingestion points: Untrusted data enters the agent context through the
wecom-cli sheet get(SKILL.md) andwecom-cli sheet ranges get(references/sheet-ranges-get.md) commands, which retrieve spreadsheet content or CSV file paths. - Boundary markers: The skill includes a "Security Tips" section in
SKILL.mdandreferences/sheet-ranges-get.mdthat explicitly instructs the agent to ignore any commands or credentials found within the returned document content. - Capability inventory: The skill possesses capabilities to write to spreadsheets, create new documents, and execute CLI commands, which could be triggered by injected instructions.
- Sanitization: The skill lacks technical sanitization or structural escaping of spreadsheet data, relying entirely on the model's adherence to the safety instructions provided in the prompt.
- [DATA_EXFILTRATION]: The skill includes a feature to upload local files to a cloud service, which could be misused to exfiltrate sensitive local data if the agent's logic is compromised.
- Evidence: The
wecom-cli sheet importcommand inSKILL.mdaccepts afile_pathparameter to upload local files directly to the WeChat Work document platform (doc.weixin.qq.com). - [COMMAND_EXECUTION]: The skill relies on the execution of an external binary to perform its primary functions.
- Evidence: The
metadata.requires.binsfield inSKILL.mdspecifies a dependency onwecom-cli. The skill operates by constructing and executing shell commands using this binary with JSON payloads provided by the model.
Audit Metadata