ai-model-wechat
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides operational guidance for using the
wx.cloud.extend.AIAPI. It includes technical details on billing paths (Growth Plan and Token Credits) and model group management, which are legitimate platform features.- [SAFE]: Security best practices are explicitly promoted, such as recommending that users avoid hardcoding API keys in client-side Mini Program code and instead use theCreateAIModelAPI to store secrets securely on the CloudBase platform.- [SAFE]: The skill uses official and trusted domains for its documentation and resource references, includingtencent.com,cloudbase.net, and the vendor's own repository oncnb.cool.- [PROMPT_INJECTION]: While the skill facilitates the use of user-provided parameters (such as model IDs) in administrative API calls likeUpdateAIModel, this functionality is necessary for its primary purpose of environment management. The instructions include extensive validation logic (the "Mandatory Two-Step Preflight") to ensure that configurations are correct and billed appropriately, which acts as a procedural safeguard.- [COMMAND_EXECUTION]: The skill utilizes management tools likecallCloudApiandenvQuery. These tools are used for legitimate resource discovery and configuration within the Tencent Cloud environment and do not involve arbitrary shell command execution.
Audit Metadata