miniprogram-development

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a code example for AI model integration that takes user-provided natural language and interpolates it into a prompt message. * Ingestion points: The userInput variable in the AI invocation script in SKILL.md. * Boundary markers: The example uses a system role prompt but lacks explicit delimiters or escaping for the user message content. * Capability inventory: The example code logs the model output to the console, which is a low-risk capability. * Sanitization: The snippet does not include input validation or output sanitization.
  • [COMMAND_EXECUTION]: The skill provides pre-defined CLI commands for opening the WeChat Developer Tools. * Evidence: Includes specific file paths for the WeChat Developer Tools executable on Windows and macOS to facilitate opening project directories via the cli.bat and cli tools.
  • [EXTERNAL_DOWNLOADS]: Recommends using Icons8 for fetching resource icons. * Evidence: Provides a specific URL format for img.icons8.com, which is a well-known service for design assets.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 06:29 AM