Навыки wecom-unified
📦

wecom-unified

Ревизия содержимого r1 Высокий риск ⚙️ Внешние команды📁 Доступ к файловой системе🌐 Доступ к сети🔑 Переменные окружения

Manage WeCom work from one workflow

WeCom work is spread across documents, schedules, meetings, files, and messages. This skill routes authorized requests to the correct WeCom CLI workflow with documented parameters and safeguards.

Поддерживает: Claude Codex Code(CC)
⚠️ 38 Плохо

Установить с помощью моего Агента

Скопируйте этот запрос в своего Агента. Он содержит каноническую страницу Skill и манифест.

Запрос агента
Review the Skillstore skill "wecom-unified" from https://skillstore.io/skills/wecomteam-wecom-unified.md and its manifest at https://skillstore.io/api/skills/wecomteam-wecom-unified/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Ваш Агент по-прежнему должен показать план и запросить все подтверждения, требуемые политикой безопасности.

Ресурсы для AI-агентов

Используйте эти ссылки, когда AI-агенту, crawler или script нужен чистый контекст вместо полной страницы.

Протестировать

Использование «wecom-unified». Schedule a review with Chen Yu tomorrow at 10:00.

Ожидаемый результат:

  • I found one matching contact: Chen Yu.
  • The schedule is ready for confirmation: Review, tomorrow 10:00 to 10:30, Chen Yu.

Использование «wecom-unified». Create a smart table for weekly project status.

Ожидаемый результат:

  • Created a smart table for weekly project status.
  • It includes fields for project name, owner, status, update date, and notes.

Использование «wecom-unified». Send the latest report to my active work chat.

Ожидаемый результат:

  • I found the latest report in the authorized file space.
  • The report was sent to your active work chat.

Аудит безопасности

Высокий риск

Most static findings are false positives caused by multilingual documentation, Markdown code formatting, example URLs, and defensive file-handling code. The audit identified one material workflow risk: the skill can automatically install an unpinned global npm package without user confirmation. No prompt-injection language, credential exfiltration, or concealed executable payload was found in the reviewed evidence.

96
Просканировано файлов
21,712
Проанализировано строк
0
Пункты проверки
0
Ложные срабатывания проигнорированы

Подтверждённые проблемы безопасности (1)

Высокий
Unpinned Global Package Installation Without Confirmation
The skill directs the agent to run `npm install -g @wecom/cli` whenever the CLI is missing or outdated, without requiring user confirmation or pinning a version. This can introduce a supply-chain change with global system impact before the requested business action begins.
The installation instruction is explicit and unconditional after a missing or old CLI check. A global, unpinned package install is externally sourced and changes the local environment.

Факторы риска

⚙️ Внешние команды (50)
references/wecomcli-calendar-cancel.md:52-53 references/wecomcli-calendar-cancel.md:53-61 references/wecomcli-calendar-freebusy.md:146-150 references/wecomcli-calendar-update.md:104-110 references/wecomcli-calendar-update.md:110-134 references/wecomcli-meeting-list.md:222-225 references/wecomcli-meeting-search.md:169-173 references/wecomcli-meeting-update.md:70-71 references/wecomcli-meeting-update.md:71-118 references/wecomcli-smartsheet-read.md:120 references/wecomcli-smartsheet-read.md:245 references/wecomcli-smartsheet-read.md:253 references/wecomcli-smartsheet-read.md:261 scripts/build_docx.py:9 scripts/build_docx.py:11 scripts/build_docx.py:12 scripts/build_docx.py:13 scripts/build_docx.py:14 scripts/build_docx.py:15 scripts/build_docx.py:75 scripts/build_docx.py:80 scripts/build_docx.py:154 scripts/build_docx.py:166 scripts/build_docx.py:257 scripts/build_docx.py:258 scripts/build_docx.py:434 scripts/build_docx.py:469 scripts/build_docx.py:470 scripts/build_docx.py:511 scripts/build_docx.py:512 scripts/build_docx.py:514 scripts/build_docx.py:530 scripts/build_docx.py:551 scripts/build_docx.py:568 scripts/build_docx.py:569 scripts/build_docx.py:570 scripts/build_docx.py:614 scripts/build_docx.py:615 scripts/build_docx.py:628 scripts/build_docx.py:637 scripts/build_docx.py:638 scripts/build_docx.py:641 scripts/build_docx.py:653 scripts/build_docx.py:685 scripts/build_docx.py:700-702 scripts/build_docx.py:702 scripts/build_docx.py:703 scripts/build_docx.py:713 scripts/build_docx.py:729 scripts/build_docx.py:739
📁 Доступ к файловой системе (8)
🌐 Доступ к сети (10)
🔑 Переменные окружения (1)
Поделиться и цитировать этот отчет

Делитесь версионным отчетом об оценке, нейтральным значком, встраиваемой карточкой и цитатами. Skillstore публикует доказательства, не решая, безопасен ли этот Skill.

Открыть версионный отчет
Оценка безопасности

Копировать ссылку на отчёт

https://skillstore.io/skills/wecomteam-wecom-unified/audits/2?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Значок Markdown

[![Skillstore security assessment](https://skillstore.io/badges/skills/wecomteam-wecom-unified/security.svg)](https://skillstore.io/skills/wecomteam-wecom-unified?utm_source=security_passport_badge)

Значок HTML

<a href="https://skillstore.io/skills/wecomteam-wecom-unified?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/wecomteam-wecom-unified/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Встраиваемая карточка

<iframe src="https://skillstore.io/embed/skills/wecomteam-wecom-unified.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Академические ссылки (APA · BibTeX · CFF)

Цитата APA

wecomteam. (2026). wecom-unified security audit report (audit version 2) [Author version unspecified]. Skillstore. https://skillstore.io/skills/wecomteam-wecom-unified/audits/2

Цитата BibTeX

@techreport{wecomteam-wecomteam-wecom-unified-2026, author = {wecomteam}, title = {wecom-unified security audit report (audit version 2)}, institution = {Skillstore}, year = {2026}, number = {2}, url = {https://skillstore.io/skills/wecomteam-wecom-unified/audits/2}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "wecom-unified security audit report (audit version 2)" version: "unspecified" type: report authors: - name: "wecomteam" date-released: "2026-08-18" url: "https://skillstore.io/skills/wecomteam-wecom-unified/audits/2" identifiers: - type: other value: "skillstore:wecomteam-wecom-unified:audit:2" description: "Skillstore immutable audit report identifier"

Оценка Skillstore

Почему такая оценка Достоверность доказательств: Средний
68
Архитектура
85
Сопровождаемость
87
Контент
65
Сообщество
83
Соответствие спецификации

Что вы можете построить

Coordinate a project meeting

Check participant availability, select a bookable room, and create an authorized meeting or schedule.

Maintain team records

Create or update approved documents, online tables, and smart tables for operational work.

Handle workplace communications

Search authorized email and files, then send a message or email through the configured account.

Попробуйте эти промпты

Find a colleague
Find the authorized WeCom contact named Li Ming and show the available matching names.
Create a schedule
Schedule a 30-minute planning session with Chen Yu tomorrow afternoon. Ask me if the time is ambiguous.
Update a smart table
In this WeCom smart table, add a record for Project Atlas with status In Progress and owner Wang Lei.
Prepare a meeting
Find a one-hour time next week when Chen Yu and Wang Lei are free, then propose available meeting rooms before creating anything.

Лучшие практики

  • Confirm the target, scope, and key parameters before irreversible changes or external sends.
  • Use a current-message link or an authorized search result to identify documents and tables.
  • Review names, times, recipients, and attachments before creating meetings or sending communications.

Избегать

  • Do not request or expose internal identifiers when readable names or links are available.
  • Do not assume a missing or ambiguous person, document, room, or time selection.
  • Do not rely on this skill for operations that the WeCom CLI or account permissions do not support.

Часто задаваемые вопросы

What does this skill require?
It requires wecom-cli, a compatible version, and an authorized WeCom account.
Can it manage documents and tables?
Yes. It supports documented workflows for documents, online tables, smart tables, and smart pages.
Can it create meetings?
Yes. It can create and manage supported online meetings and schedules after required details are resolved.
Can it send email and messages?
Yes. It supports documented email and recent-session messaging workflows through the authorized account.
Does it support recurring meetings?
No. The documented workflows do not support recurring meeting or schedule operations.
Will it show internal IDs?
No. The skill is designed to use readable names and links rather than internal identifiers in final responses.

Сведения для разработчиков

Автор

wecomteam

Лицензия

MIT

Ревизия Skillstore

r1

Примечание о версии

Автор не указал версию.

Ссылка

e22f0e5c175a84e01097fa734ec2a74420c14771

Актуальность поддержки

19.08.2026

Использование

0 загрузок · 0 просмотров

Структура файлов

📁 references/

📄 wecomcli-calendar-agenda.md

📄 wecomcli-calendar-cancel.md

📄 wecomcli-calendar-create.md

📄 wecomcli-calendar-freebusy.md

📄 wecomcli-calendar-meeting-room.md

📄 wecomcli-calendar-search.md

📄 wecomcli-calendar-update.md

📄 wecomcli-calendar.md

📄 wecomcli-contact.md

📄 wecomcli-disk.md

📄 wecomcli-doc-contents-append.md

📄 wecomcli-doc-contents-overwrite.md

📄 wecomcli-doc-create.md

📄 wecomcli-doc-manage-doc-members-update.md

📄 wecomcli-doc-manage-doc-names-update.md

📄 wecomcli-doc-manage-doc-rules-update.md

📄 wecomcli-doc-manage.md

📄 wecomcli-doc.md

📄 wecomcli-email-forward-mail.md

📄 wecomcli-email-get-mail.md

📄 wecomcli-email-reply-mail.md

📄 wecomcli-email-search-mail.md

📄 wecomcli-email-security.md

📄 wecomcli-email-send-mail.md

📄 wecomcli-email-send-schedule.md

📄 wecomcli-email.md

📄 wecomcli-media.md

📄 wecomcli-meeting-cancel.md

📄 wecomcli-meeting-create.md

📄 wecomcli-meeting-list.md

📄 wecomcli-meeting-original-get.md

📄 wecomcli-meeting-search.md

📄 wecomcli-meeting-update.md

📄 wecomcli-meeting.md

📄 wecomcli-message.md

📄 wecomcli-sheet-contents-update.md

📄 wecomcli-sheet-ranges-get.md

📄 wecomcli-sheet-rows-append.md

📄 wecomcli-sheet-subsheets-add.md

📄 wecomcli-sheet-subsheets-delete.md

📄 wecomcli-sheet.md

📄 wecomcli-smartpage-data-driven-pages.md

📄 wecomcli-smartpage-edit.md

📄 wecomcli-smartpage-formula-arraylist.md

📄 wecomcli-smartpage-formula-datetime.md

📄 wecomcli-smartpage-formula-logic.md

📄 wecomcli-smartpage-formula-math.md

📄 wecomcli-smartpage-formula-operators.md

📄 wecomcli-smartpage-formula-pageblock.md

📄 wecomcli-smartpage-formula-reference.md

📄 wecomcli-smartpage-formula-templates.md

📄 wecomcli-smartpage-formula-text.md

📄 wecomcli-smartpage-formula-user.md

📄 wecomcli-smartpage-mdx-syntax.md

📄 wecomcli-smartpage.md

📄 wecomcli-smartsheet-chart-types.md

📄 wecomcli-smartsheet-common.md

📄 wecomcli-smartsheet-edit.md

📄 wecomcli-smartsheet-field-types.md

📄 wecomcli-smartsheet-formula.md

📄 wecomcli-smartsheet-read.md

📄 wecomcli-smartsheet-record-values.md

📄 wecomcli-smartsheet-template-ai_efficiency.md

📄 wecomcli-smartsheet-template-connect_to_app.md

📄 wecomcli-smartsheet-template-financial_accounting.md

📄 wecomcli-smartsheet-template-hr_and_administration.md

📄 wecomcli-smartsheet-template-ledger_records.md

📄 wecomcli-smartsheet-template-manufacturing.md

📄 wecomcli-smartsheet-template-marketing.md

📄 wecomcli-smartsheet-template-office_essentials.md

📄 wecomcli-smartsheet-template-personal_efficiency.md

📄 wecomcli-smartsheet-template-procurement_logistics.md

📄 wecomcli-smartsheet-template-project_management.md

📄 wecomcli-smartsheet-template-rd_process_customer.md

📄 wecomcli-smartsheet-template-rd_process_ops.md

📄 wecomcli-smartsheet-template-rd_process_project.md

📄 wecomcli-smartsheet-template-rd_process_research.md

📄 wecomcli-smartsheet-template-sales_and_operations.md

📄 wecomcli-smartsheet-template-store_management.md

📄 wecomcli-smartsheet-template-team_tasks.md

📄 wecomcli-smartsheet-template-wechat_customer.md

📄 wecomcli-smartsheet-template-work_report.md

📄 wecomcli-smartsheet-templates.md

📄 wecomcli-smartsheet-view-types.md

📄 wecomcli-smartsheet-webhook-examples.md

📄 wecomcli-smartsheet-webhook.md

📄 wecomcli-smartsheet.md

📄 wecomcli-todo-create.md

📄 wecomcli-todo-delete.md

📄 wecomcli-todo-finish.md

📄 wecomcli-todo-get.md

📄 wecomcli-todo-list.md

📄 wecomcli-todo-update.md

📄 wecomcli-todo.md

📁 scripts/

📄 build_docx.py

📄 SKILL.md