wecomcli-doc

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能的功能范围与“企业微信文档/智能表格管理”目的基本一致,未见明显凭证窃取或无关数据外传迹象;但其核心完全依赖未在文档中验证来源的外部 CLI,且包含不可逆写删操作,并引入另一技能作为辅助依赖。综合看更像高风险的黑箱集成而非明确恶意内容。

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
Apr 2, 2026, 02:55 AM
Package URL
pkg:socket/skills-sh/WeComTeam%2Fwecom-cli%2Fwecomcli-doc%2F@e2809e4d1386321ed120735f9710ff1d85baa0cc