wecomcli-preflight

Warn

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on the execution of shell commands (openclaw config get and openclaw config set) to query and modify the host platform's configuration.
  • [PRIVILEGE_ESCALATION]: It attempts to automatically modify the tool execution whitelist (tools.alsoAllow) to grant permissions to the 'wecom-openclaw-plugin'. Although this targets the vendor's own resource, automatically altering security policies to bypass tool restrictions is a sensitive operation that usually requires explicit user oversight.
  • [DATA_EXPOSURE]: The skill reads the current tools.profile and tools.alsoAllow settings, exposing the security configuration and the list of other permitted tools in the agent's environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 18, 2026, 10:33 AM
Security Audit — agent-trust-hub — wecomcli-preflight