cloudbase-wechat-integration

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for handling external data from WeChat payment callbacks (e.g., xpay_goods_deliver_notify). Evidence:
  • Ingestion points: References in virtual-payment.md and mini-program-pay.md describe receiving HTTP callback notifications from WeChat.
  • Boundary markers: The skill explicitly instructs developers to preserve generated callback verification and decryption logic to ensure data integrity.
  • Capability inventory: The instructions involve writing results to CloudBase databases and triggering business fulfillment logic.
  • Sanitization: The skill mandates server-side validation of amount and product data before processing any transaction.
  • [SAFE]: No malicious code, obfuscation, or unauthorized access patterns were detected. All external links point to official documentation from trusted or well-known sources (Tencent and WeChat).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 01:08 AM
Security Audit — agent-trust-hub — cloudbase-wechat-integration