wxa-find-skills

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches mini-program skill templates and assets from the official 'TencentCloudBase/awesome-miniprogram-skills' GitHub repository.
  • [COMMAND_EXECUTION]: Executes the mp-skills CLI tool using npx to manage skills within the local project environment, including searching, listing, and setting up configurations.
  • [REMOTE_CODE_EXECUTION]: Downloads and installs external code components into the user's local mini-program project. This behavior is the primary purpose of the skill and targets vendor-controlled infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 09:11 AM
Security Audit — agent-trust-hub — wxa-find-skills