wecomcli-todo
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from user messages and external Enterprise WeChat todo records without sufficient isolation, presenting a surface for indirect instructions to influence agent behavior.\n
- Ingestion points: User-provided task details in conversation and todo item content retrieved from tool outputs in references/todo-list.md and references/todo-get.md.\n
- Boundary markers: The skill lacks explicit boundary markers or delimiters (such as XML tags or unique markers) to isolate external task data from the system prompt.\n
- Capability inventory: The skill utilizes the wecom-cli tool to perform sensitive actions including creating, updating, and deleting todo items in an enterprise environment.\n
- Sanitization: There is no evidence of sanitization, escaping, or validation of the todo content before it is passed to tool arguments or presented to the agent's context.
Audit Metadata