tencent-docs

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The setup.sh script is executed to configure the environment, install the mcporter dependency, and manage authentication tokens. The OperationSheet tool also facilitates the execution of JavaScript code for spreadsheet automation.\n- [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch document content via the scrape_url tool and installs the mcporter utility from the npm registry. It also interacts with official Tencent Docs domains for configuration and updates.\n- [REMOTE_CODE_EXECUTION]: An update mechanism in SKILL.md queries an official endpoint to retrieve version information and potential update instructions, which the agent is directed to follow.\n- [PROMPT_INJECTION]: Documentation files like sheet/api/js-script-rule.md contain defensive prompts intended to prevent users from overriding the agent's core safety guidelines or accessing internal configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 04:45 PM