shopping-skill

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill establishes a well-defined business logic for commerce operations, including explicit instructions in SKILL.md that prevent the AI agent from fabricating product or store identifiers.- [SAFE]: All external interactions are conducted through official WeChat Mini-Program APIs (wx.modelContext, wx.getStorageSync) and Tencent Cloud Base infrastructure (wx.cloud.callFunction), which are the standard and secure methods for this platform.- [SAFE]: No patterns of prompt injection, data exfiltration, or malicious obfuscation were identified. The code follows best practices by separating sensitive business logic into cloud functions and using strict input schemas defined in mcp.json.- [SAFE]: Dependencies are limited to official SDKs (wx-server-sdk), and there are no signs of remote code execution or unauthorized system access.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 04:58 AM
Security Audit — agent-trust-hub — shopping-skill