wechat-miniprogram-store-kit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides auditing scripts (audit_miniprogram.py) and asset initialization tools (init_release_assets.py) that run locally to help developers prepare for WeChat Mini Program submission. The audit script includes defensive features designed to detect and warn users about hardcoded secrets and insecure network configurations.\n- [INDIRECT_PROMPT_INJECTION]: The skill reads untrusted source code from a user's repository via the audit_miniprogram.py script to generate an audit report for the agent. The risk is minimized by truncating excerpts and escaping markdown control characters.\n
- Ingestion points: The audit_miniprogram.py script reads source files (e.g., .js, .ts, .wxml) within the target repository.\n
- Boundary markers: The audit report uses structural markdown headers and code blocks to separate analyzed content from instructions.\n
- Capability inventory: The skill executes Python scripts to perform filesystem reads and generate reports; the agent uses these reports to suggest documentation and configuration changes.\n
- Sanitization: Source code excerpts are truncated to 180 characters and backticks (`) are replaced with similar-looking characters (ˋ) to prevent breakout from markdown code blocks in the generated report.
Audit Metadata