auth-wechat-miniprogram
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill's instructions and code examples adhere to official CloudBase implementation patterns for WeChat authentication.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data, creating a potential attack surface. 1. Ingestion points: Environment ID (env) and encrypted phone codes (phoneCode) are requested from the user. 2. Boundary markers: None present. 3. Capability inventory: No dangerous tools (shell execution, file system writes, or network exfiltration) are utilized by the skill scripts. 4. Sanitization: No specific sanitization of the input identifiers is mentioned. Given the total absence of exploitable capabilities, this ingestion surface is considered safe.
- [EXTERNAL_DOWNLOADS]: The skill references the official wx-server-sdk and @cloudbase/js-sdk packages. These are verified vendor resources from Tencent CloudBase and are used appropriately for their intended functionality.
Audit Metadata