CtrlK
BlogDocsLog inGet started
Tessl Logo

dingtalk-drive

钉钉文件管理(存储层,覆盖钉盘与文档空间)。Use when 用户说 钉盘/文档空间/我的文档中的普通文件或文件夹、查找/上传/下载/复制/移动/重命名/删除/回收站/权限/元信息,或本地与钉盘文件夹比较、拉取、推送、双向同步;也承接在线文档节点的存储管理。文档正文编辑与导出走 dingtalk-doc;明确的知识库空间及空间内节点组织走 dingtalk-wiki。命令前缀:dws drive。

72

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Low

Low-risk findings.

1 low severity finding. Worth noting, but not necessarily harmful.

Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

运行时通过 `dws drive +search/+list/+recent` 等在钉盘侧读取“节点名称/关键词/条目集合”等由用户在钉盘中创建的内容来选取具体 `dentryUuid` 并完成后续操作(例如先 search 后据真实返回执行),因此存在从外部可写入的钉盘条目中进入 Agent 的自由文本载荷风险。

Report incorrect finding
Repository
DingTalk-Real-AI/dingtalk-workspace-cli
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.