cloudbase-document-database-in-wechat-miniprogram

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides legitimate documentation and code snippets for the official Tencent CloudBase SDK. Analysis of all provided files, including the activation contract and operational guides, revealed no malicious patterns, prompt injections, or unauthorized exfiltration attempts.
  • [INDIRECT_PROMPT_INJECTION]: The skill enables the agent to query database collections which could contain untrusted data. 1. Ingestion points: db.collection().get() calls in SKILL.md and complex-queries.md. 2. Boundary markers: Absent. 3. Capability inventory: Database CRUD operations; no OS-level execution or network exfiltration tools are defined in the provided files. 4. Sanitization: The skill recommends manual data validation and the use of database security rules (security-rules.md) to control access.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:09 AM
Security Audit — agent-trust-hub — cloudbase-document-database-in-wechat-miniprogram