Historial de auditorías
wecom-unified - 2 auditorías
Comparación de versiones
Cambios de capacidades y hallazgos entre versiones auditadas, primero las más recientes.
18 ago 2026, 08:30
Most static findings are false positives caused by multilingual documentation, Markdown code formatting, example URLs, and defensive file-handling code. The audit identified one material workflow risk: the skill can automatically install an unpinned global npm package without user confirmation. No prompt-injection language, credential exfiltration, or concealed executable payload was found in the reviewed evidence.
Preocupaciones de seguridad confirmadas (1)
Factores de riesgo
⚙️ Comandos externos (50)
📁 Acceso al sistema de archivos (8)
🌐 Acceso a red (10)
🔑 Variables de entorno (1)
18 ago 2026, 08:30
Most static findings are false positives caused by multilingual documentation, Markdown code formatting, example URLs, and defensive file-handling code. The audit identified one material workflow risk: the skill can automatically install an unpinned global npm package without user confirmation. No prompt-injection language, credential exfiltration, or concealed executable payload was found in the reviewed evidence.