CtrlK
BlogDocsLog inGet started
Tessl Logo

wecom-doc

当用户提到企业微信文档、智能表格、创建文档、编辑文档、写文档时启用。优先复用 wecom channel 自动写入的文档 MCP 配置,并通过 mcporter 调用文档能力。

75

Quality

95%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Security

1 high severity finding. You should review these findings carefully before considering using this skill.

High

W007: Insecure credential handling detected in skill instructions.

What this means

The skill handles credentials insecurely by requiring the agent to include secret values verbatim in its generated output. This exposes credentials in the agent’s context and conversation history, creating a risk of data exfiltration.

Why it was flagged

The skill instructs the agent to read a local config or accept a user-provided URL/JSON and then insert the extracted URL verbatim into mcporter CLI commands (--url "<url>"), which can expose embedded tokens/credentials in the LLM output — a high-risk secret-handling pattern.

Report incorrect finding

Low

Low-risk findings.

1 low severity finding. Worth noting, but not necessarily harmful.

Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

在运行时会读取操作用户可能提供的 `StreamableHttp URL` / `JSON Config`(SKILL.md:52-60),随后通过 `mcporter config add wecom-doc --type streamable-http --url "<url>"` 配置 `wecom-doc` 并由 MCP 读取其内容,从而可能把“URL 对应的网页/远端文本”(外部来源的免费文本)喂入 LLM 上下文。

Repository
BytePioneer-AI/openclaw-china
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.