wxa-skills-generate

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/probe.mjs uses child_process.spawn to execute standard commands for the WeChat Developer Tools CLI, including open, auto, quit, and trust-project. These operations are limited to the developer's local environment and target the provided project path.
  • [DYNAMIC_EXECUTION]: The scripts/probe-lib.mjs library utilizes miniProgram.evaluate and new Function to inject instrumentation code into the Mini Program's runtime environment for capturing network requests and automating UI interactions during the probing phase. This is a core feature of the developer tool for ensuring accurate API schema extraction.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes and analyzes untrusted external data (Mini Program source code) provided by the user. While this represents a potential attack surface for indirect prompt injection, the skill defines strict templates, boundary markers, and self-check scripts (scripts/check-artifacts.mjs) to maintain fidelity and limit the impact of untrusted input.
  • [SAFE_PRACTICE]: The skill implements a specific safety mechanism in references/RUNTIME_PROBE.md to identify and skip 'destructive' APIs (e.g., account deletion, data clearing) during automated testing unless explicitly confirmed by a user, preventing accidental data loss during the generation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 02:32 PM
Security Audit — agent-trust-hub — wxa-skills-generate