wecomcli-manage-schedule

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能的业务范围与“企业微信日程管理”基本一致,未见明显越权读取本地敏感文件或将数据路由到明显异常第三方域名;但其全部功能建立在不可验证来源的外部 CLI `wecom-cli` 之上,且文档声称其为官方工具而现有证据无法证实。这使其更像是高风险供应链依赖而非已确认恶意技能。综合判断为 SUSPICIOUS。

Confidence: 83%Severity: 82%
Audit Metadata
Analyzed At
Mar 29, 2026, 05:09 PM
Package URL
pkg:socket/skills-sh/WeComTeam%2Fwecom-cli%2Fwecomcli-manage-schedule%2F@dbeafaf8f8c9a9ad50af2831e05b373f0d60fe1e