wecomcli-sheet

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external spreadsheets that are considered untrusted sources, providing an attack surface for instructions hidden within cell data.
  • Ingestion points: Untrusted data enters the agent context through the wecom-cli sheet get (SKILL.md) and wecom-cli sheet ranges get (references/sheet-ranges-get.md) commands, which retrieve spreadsheet content or CSV file paths.
  • Boundary markers: The skill includes a "Security Tips" section in SKILL.md and references/sheet-ranges-get.md that explicitly instructs the agent to ignore any commands or credentials found within the returned document content.
  • Capability inventory: The skill possesses capabilities to write to spreadsheets, create new documents, and execute CLI commands, which could be triggered by injected instructions.
  • Sanitization: The skill lacks technical sanitization or structural escaping of spreadsheet data, relying entirely on the model's adherence to the safety instructions provided in the prompt.
  • [DATA_EXFILTRATION]: The skill includes a feature to upload local files to a cloud service, which could be misused to exfiltrate sensitive local data if the agent's logic is compromised.
  • Evidence: The wecom-cli sheet import command in SKILL.md accepts a file_path parameter to upload local files directly to the WeChat Work document platform (doc.weixin.qq.com).
  • [COMMAND_EXECUTION]: The skill relies on the execution of an external binary to perform its primary functions.
  • Evidence: The metadata.requires.bins field in SKILL.md specifies a dependency on wecom-cli. The skill operates by constructing and executing shell commands using this binary with JSON payloads provided by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:54 AM
Security Audit — agent-trust-hub — wecomcli-sheet