auth-wechat-miniprogram

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill's instructions and code examples adhere to official CloudBase implementation patterns for WeChat authentication.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data, creating a potential attack surface. 1. Ingestion points: Environment ID (env) and encrypted phone codes (phoneCode) are requested from the user. 2. Boundary markers: None present. 3. Capability inventory: No dangerous tools (shell execution, file system writes, or network exfiltration) are utilized by the skill scripts. 4. Sanitization: No specific sanitization of the input identifiers is mentioned. Given the total absence of exploitable capabilities, this ingestion surface is considered safe.
  • [EXTERNAL_DOWNLOADS]: The skill references the official wx-server-sdk and @cloudbase/js-sdk packages. These are verified vendor resources from Tencent CloudBase and are used appropriately for their intended functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — auth-wechat-miniprogram