Dingtalk Notify

Security checks across malware telemetry and agentic risk

Overview

This DingTalk notification skill appears purpose-aligned, but it can send messages and files externally and keep local send records with weak disclosure and a broad trigger phrase.

Review this skill before installing. Use it only if you are comfortable with content and files being sent to DingTalk, confirm the target recipient before each send, and check or limit any local notification logs so sensitive workplace data is not retained unexpectedly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrase "工作通知" is generic workplace language and is likely to match ordinary user conversation rather than an explicit request to invoke this skill. That increases the chance of accidental activation, which is risky here because the skill can send messages and files to an external DingTalk recipient.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill enables outbound message and file transmission to DingTalk and also states that send records are stored locally, but it does not present an explicit warning about external data transfer, recipient identity, or retention of notification logs. In practice, this can cause users or agents to send sensitive content off-platform or persist metadata without informed consent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal