wecomcli-smartsheet

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS but not malicious. The main functionality aligns with SmartSheet management and the `wecom-cli` dependency appears to be an official same-org npm package, which keeps supply-chain risk moderate. The main security concern is the fallback webhook path: it intentionally routes record data to an arbitrary user-provided endpoint outside the normal WeCom/CLI channel, creating a meaningful data-leak risk if the endpoint is untrusted or mistyped. Overall this is a coherent enterprise integration skill with medium risk from external CLI trust and webhook-based data egress, not evidence of credential harvesting or malware.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Sep 14, 2026, 07:04 PM
Package URL
pkg:socket/skills-sh/wecomteam%2Fwecom-cli%2Fwecomcli-smartsheet%2F@53de9680e978ddfd50d6c5b3cca3b716d6a2f9772bcc701a72a88860f248a435
Security Audit — socket — wecomcli-smartsheet