wxa-skills-validate

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes external commands via the WeChat DevTools CLI to perform project builds and component validation. It uses a helper library to spawn subprocesses and includes a sanitization function to escape shell arguments.
  • Evidence: lib.mjs defines runCli which uses spawn("/bin/sh", ["-c", shellCmd]) to run commands, and a shellQuote function to sanitize input strings for the shell.
  • [SAFE]: The skill implements a safety mechanism (Rule V019) to detect "destructive" operations such as account deletion or logging out. These commands are flagged and require a specific flag (--confirm-destructive) to be executed.
  • Evidence: lib.mjs contains the DESTRUCTIVE_KEYWORDS list and the isDestructiveApi function used by execute.mjs to block sensitive operations by default.
  • [SAFE]: The skill modifies the project's project.config.json to automatically ignore validation logs and artifacts. This is a standard development practice to prevent infinite build loops caused by file watchers.
  • Evidence: validate.mjs contains the ensureValidateIgnoreConfig function that updates packOptions.ignore and watchOptions.ignore in the project configuration.
  • [SAFE]: The skill performs static analysis on project source code using a variety of regex-based rules (V001-V019) defined in validate.mjs to ensure compliance with the WeChat Mini Program AI framework.
  • Evidence: VALIDATE_RULES.md and validate.mjs detail the validation suite for WXML, WXSS, and JavaScript files within the skill subpackages.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 02:33 PM
Security Audit — agent-trust-hub — wxa-skills-validate