dingtalk-daily

Security checks across malware telemetry and agentic risk

Overview

This DingTalk report skill matches its stated purpose, but it gives an agent broad company-report and employee-ID access without clear authorization boundaries.

Install only if you can provide a least-privilege DingTalk internal app credential and trust the agent to handle workplace report data. Before each action, verify the target user ID, date range, report text, recipients, and chat notification setting; avoid using broad employee search unless you are authorized to look up that person.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger phrases are broad enough that ordinary workplace language such as '工作总结' or '查看我的日报' could invoke the skill without sufficiently explicit user intent. In a skill that can query logs, search employee identifiers, and send reports, accidental invocation may expose sensitive work data or perform unintended actions.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill documents the ability to search user employee IDs by name but provides no privacy notice, authorization boundary, or use restriction. In an enterprise context, employee identifiers are sensitive directory information, and exposing lookup capability without guardrails can enable unnecessary enumeration, stalking, or misuse of internal identity data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal