ai-model-wechat

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides operational guidance for using the wx.cloud.extend.AI API. It includes technical details on billing paths (Growth Plan and Token Credits) and model group management, which are legitimate platform features.- [SAFE]: Security best practices are explicitly promoted, such as recommending that users avoid hardcoding API keys in client-side Mini Program code and instead use the CreateAIModel API to store secrets securely on the CloudBase platform.- [SAFE]: The skill uses official and trusted domains for its documentation and resource references, including tencent.com, cloudbase.net, and the vendor's own repository on cnb.cool.- [PROMPT_INJECTION]: While the skill facilitates the use of user-provided parameters (such as model IDs) in administrative API calls like UpdateAIModel, this functionality is necessary for its primary purpose of environment management. The instructions include extensive validation logic (the "Mandatory Two-Step Preflight") to ensure that configurations are correct and billed appropriately, which acts as a procedural safeguard.- [COMMAND_EXECUTION]: The skill utilizes management tools like callCloudApi and envQuery. These tools are used for legitimate resource discovery and configuration within the Tencent Cloud environment and do not involve arbitrary shell command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 10:35 AM