wecomcli-smartsheet

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the wecom-cli binary to perform spreadsheet operations, using JSON-formatted parameters. This is the intended and primary operation mode for the skill.\n- [EXTERNAL_DOWNLOADS]: The skill metadata identifies wecom-cli as a required external binary dependency for all spreadsheet management tasks.\n- [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by reading record data from external spreadsheets via smartsheet_get_records.\n
  • Ingestion points: Data retrieved from smartsheets using smartsheet_get_records (SKILL.md).\n
  • Boundary markers: The instructions do not define delimiters or warnings to isolate instructions found in spreadsheet data.\n
  • Capability inventory: Shell execution of wecom-cli and file system access through image_path and file_path parameters (SKILL.md).\n
  • Sanitization: The skill does not specify procedures for validating or sanitizing data ingested from the spreadsheets.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 06:35 AM