specialist-engineering-wechat-mini-program-developer

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a well-structured prompt for a subagent specialized in WeChat Mini Program engineering. All instructions and code samples align with official platform guidelines and standard development practices.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a template that interpolates user questions into a subagent prompt.
  • Ingestion points: The user's question is appended to the end of the prompt provided to the Agent tool in SKILL.md.
  • Boundary markers: The input is not surrounded by specific delimiters or instructions to ignore embedded commands, which is a common surface for indirect injection.
  • Capability inventory: The spawned subagent is configured for specialized programming assistance and is not granted access to sensitive host tools (e.g., shell, local filesystem, or credential stores), significantly limiting the potential impact of an injection.
  • Sanitization: No specific sanitization logic is present for the interpolated user input.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:50 PM
Security Audit — agent-trust-hub — specialist-engineering-wechat-mini-program-developer