wecomcli-todo
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a local binary
wecom-clito perform tasks. Inputs are passed via a structured JSON parameter, which is a secure method of command execution. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text for task details. The vulnerability surface is mitigated by high-priority security instructions that forbid the agent from treating tool output as instructions.
- [SAFE]: The skill implements safety measures such as mandatory pre-checks from a shared skill and instructions to protect internal system tokens and IDs from user exposure.
Audit Metadata