weapp-devtools-e2e-best-practices
Pass
Audited by Gen Agent Trust Hub on Oct 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive instructions for managing WeChat DevTools E2E workflows, specifically for the
weapp-viteecosystem. No malicious patterns or security vulnerabilities were detected. - [CREDENTIALS_UNSAFE]: The skill contains explicit safety instructions to protect sensitive data. It mandates that diagnostic logs must only record installation and port status, and strictly forbids the recording or output of account tickets, login credentials, or lease tokens.
- [COMMAND_EXECUTION]: The skill references standard development and testing tools such as
vitest,pnpm,execa, and local TypeScript scripts (e.g.,scripts/check-e2e-ide-shared-launch.ts). These are used for project-specific automation and do not involve arbitrary or untrusted command execution. - [EXTERNAL_DOWNLOADS]: References to external sites are limited to the official WeChat developer documentation (developers.weixin.qq.com) for downloading the IDE, which is a trusted vendor source in this context.
- [PRIVILEGE_ESCALATION]: The instructions for resource management (machine leases) are implemented as local file-based locking mechanisms for concurrency control in testing environments. They do not attempt to gain administrative privileges or modify system-wide configurations beyond the scope of the developer's worktree.
- [DATA_EXFILTRATION]: There are no patterns of network exfiltration. The skill emphasizes local logging and visual acceptance (screenshots/logs) for developers rather than sending data to external third-party servers.
Audit Metadata