Audit-Verlauf
wecom-unified - 2 Audits
Versionsvergleich
Änderungen an Fähigkeiten und Befunden über geprüfte Versionen hinweg, neueste zuerst.
18. Aug. 2026, 08:30
Most static findings are false positives caused by multilingual documentation, Markdown code formatting, example URLs, and defensive file-handling code. The audit identified one material workflow risk: the skill can automatically install an unpinned global npm package without user confirmation. No prompt-injection language, credential exfiltration, or concealed executable payload was found in the reviewed evidence.
Bestätigte Sicherheitsbedenken (1)
Risikofaktoren
⚙️ Externe Befehle (50)
📁 Dateisystemzugriff (8)
🌐 Netzwerkzugriff (10)
🔑 Umgebungsvariablen (1)
18. Aug. 2026, 08:30
Most static findings are false positives caused by multilingual documentation, Markdown code formatting, example URLs, and defensive file-handling code. The audit identified one material workflow risk: the skill can automatically install an unpinned global npm package without user confirmation. No prompt-injection language, credential exfiltration, or concealed executable payload was found in the reviewed evidence.