wecomcli-smartsheet
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS but not malicious. The main functionality aligns with SmartSheet management and the `wecom-cli` dependency appears to be an official same-org npm package, which keeps supply-chain risk moderate. The main security concern is the fallback webhook path: it intentionally routes record data to an arbitrary user-provided endpoint outside the normal WeCom/CLI channel, creating a meaningful data-leak risk if the endpoint is untrusted or mistyped. Overall this is a coherent enterprise integration skill with medium risk from external CLI trust and webhook-based data egress, not evidence of credential harvesting or malware.
Confidence: 87%Severity: 56%
Audit Metadata