Audit History
wecom-unified - 2 audits
Version comparison
Capability and finding changes across audited versions, newest first.
Aug 18, 2026, 08:30 AM
Most static findings are false positives caused by multilingual documentation, Markdown code formatting, example URLs, and defensive file-handling code. The audit identified one material workflow risk: the skill can automatically install an unpinned global npm package without user confirmation. No prompt-injection language, credential exfiltration, or concealed executable payload was found in the reviewed evidence.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (50)
📁 Filesystem access (8)
🌐 Network access (10)
🔑 Env variables (1)
Aug 18, 2026, 08:30 AM
Most static findings are false positives caused by multilingual documentation, Markdown code formatting, example URLs, and defensive file-handling code. The audit identified one material workflow risk: the skill can automatically install an unpinned global npm package without user confirmation. No prompt-injection language, credential exfiltration, or concealed executable payload was found in the reviewed evidence.