order-skill

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows standard WeChat Mini Program architecture, utilizing official cloud development APIs (wx.cloud.callFunction, wx-server-sdk) and database operations within the intended platform scope.- [SAFE]: Instructions throughout SKILL.md and the apis/ directory explicitly prohibit the AI agent from fabricating identifiers like restaurantId or orderId, which serves as a safeguard against common hallucination and functional bypass issues.- [SAFE]: Data handling is restricted to the specific orders collection. The use of openid is consistent with WeChat's scoped user identification system.- [SAFE]: External dependencies are limited to the official vendor SDK. Remote image references point to picsum.photos, a well-known service for development placeholders.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 04:58 AM
Security Audit — agent-trust-hub — order-skill