История аудитов
wecom-unified - 2 аудиты
Сравнение версий
Изменения возможностей и находок между проверенными версиями, сначала новые.
18 авг. 2026 г., 08:30
Most static findings are false positives caused by multilingual documentation, Markdown code formatting, example URLs, and defensive file-handling code. The audit identified one material workflow risk: the skill can automatically install an unpinned global npm package without user confirmation. No prompt-injection language, credential exfiltration, or concealed executable payload was found in the reviewed evidence.
Подтверждённые проблемы безопасности (1)
Факторы риска
⚙️ Внешние команды (50)
📁 Доступ к файловой системе (8)
🌐 Доступ к сети (10)
🔑 Переменные окружения (1)
18 авг. 2026 г., 08:30
Most static findings are false positives caused by multilingual documentation, Markdown code formatting, example URLs, and defensive file-handling code. The audit identified one material workflow risk: the skill can automatically install an unpinned global npm package without user confirmation. No prompt-injection language, credential exfiltration, or concealed executable payload was found in the reviewed evidence.