tencent-docs
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
setup.shscript is executed to configure the environment, install themcporterdependency, and manage authentication tokens. TheOperationSheettool also facilitates the execution of JavaScript code for spreadsheet automation.\n- [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch document content via thescrape_urltool and installs themcporterutility from the npm registry. It also interacts with official Tencent Docs domains for configuration and updates.\n- [REMOTE_CODE_EXECUTION]: An update mechanism inSKILL.mdqueries an official endpoint to retrieve version information and potential update instructions, which the agent is directed to follow.\n- [PROMPT_INJECTION]: Documentation files likesheet/api/js-script-rule.mdcontain defensive prompts intended to prevent users from overriding the agent's core safety guidelines or accessing internal configurations.
Audit Metadata