dingtalk-troubleshoot
钉钉连接器问题排查。包含 dws CLI 常见错误处理、授权问题排查和连接故障诊断。 当 dws 命令执行失败、授权异常、连接中断时自动激活。
Security Findings
Remote code execution pipe
Downloads and pipes to shell: curl -fsSL https://github.com/open-dingtalk/dingtalk-workspace-cli/releases/latest/download/install.sh | sh
External binary download
Prerequisite downloads from non-standard source: https://github.com/open-dingtalk/dingtalk-workspace-cli/releases/latest/download/install.sh
Low-provenance referenced GitHub repo
Referenced repo open-dingtalk/dingtalk-workspace-cli not found (deleted / renamed / private): https://github.com/open-dingtalk/dingtalk-workspace-cli/releases/latest/download/install.sh
Unreachable / dead referenced source
Referenced executable source is returning 404 (resource gone): https://github.com/open-dingtalk/dingtalk-workspace-cli/releases/latest/download/install.sh
Recently created account
Account was 0d old when repo was created
Workflow makes outbound network call
[.github/workflows/ai-fix-and-test.yml] curl -s -X POST https://api.openai.com/v1/chat/completions
Versions
1- Scanned Jul 19, 2026, 10:01 AMHigh