dingtalk-workspace-cli

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities generally match its DingTalk automation purpose, but the trust model is weak: it runs unpinned remote installers, installs an external binary, auto-installs additional agent skills, and then uses DingTalk credentials to perform organization actions. With no provided verification that the GitHub org and binary are officially operated by DingTalk, the install and credential-forwarding footprint is higher risk than the description implies.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Mar 27, 2026, 07:49 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fdingtalk-workspace-cli%2F@63fb380ea536bfe62279ecda17187cdcc1e25988