wechat-official-account-qr

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs image downloads from open.weixin.qq.com, which is the official domain for WeChat (Tencent), a well-known and recognized service provider. These network operations are limited to fetching static image content and do not involve untrusted remote code execution.\n- [SAFE]: All user-provided account IDs are strictly sanitized using a regular expression (^[A-Za-z0-9_-]{3,128}$) before being incorporated into URLs or local file paths. This prevents command injection, URL manipulation, and path traversal attacks.\n- [SAFE]: The skill uses local file system access solely for its stated purpose: saving QR code images to ensure they display correctly in the agent's user interface. It does not attempt to access sensitive system files or credentials.\n- [SAFE]: No evidence of obfuscation, credential harvesting, persistence mechanisms, or indirect prompt injection surfaces was identified in the analyzed scripts or instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 05:07 PM
Security Audit — agent-trust-hub — wechat-official-account-qr