wecomcli-preflight
Warn
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on the execution of shell commands (
openclaw config getandopenclaw config set) to query and modify the host platform's configuration. - [PRIVILEGE_ESCALATION]: It attempts to automatically modify the tool execution whitelist (
tools.alsoAllow) to grant permissions to the 'wecom-openclaw-plugin'. Although this targets the vendor's own resource, automatically altering security policies to bypass tool restrictions is a sensitive operation that usually requires explicit user oversight. - [DATA_EXPOSURE]: The skill reads the current
tools.profileandtools.alsoAllowsettings, exposing the security configuration and the list of other permitted tools in the agent's environment.
Audit Metadata