auth-wechat-miniprogram
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents handling external data within cloud functions, which represents an indirect prompt injection surface where untrusted client input could influence agent behavior or backend logic.
- Ingestion points: The
eventobject in cloud function entry points (exports.main) inreferences/extended-guide.mdreceives data directly from the Mini Program client. - Boundary markers: The instructions correctly emphasize using
cloud.getWXContext()to retrieve system-verified identity markers rather than relying on user-supplied IDs in theeventpayload. - Capability inventory: The documented functions have the capability to query databases, perform authorization checks, and return data to the client environment.
- Sanitization: The skill promotes the best practice of using platform-verified identifiers (
OPENID) for all user-specific operations and authorization logic, significantly reducing the risk of identity spoofing.
Audit Metadata