wxa-skills-validate
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes external commands via the WeChat DevTools CLI to perform project builds and component validation. It uses a helper library to spawn subprocesses and includes a sanitization function to escape shell arguments.
- Evidence:
lib.mjsdefinesrunCliwhich usesspawn("/bin/sh", ["-c", shellCmd])to run commands, and ashellQuotefunction to sanitize input strings for the shell. - [SAFE]: The skill implements a safety mechanism (Rule V019) to detect "destructive" operations such as account deletion or logging out. These commands are flagged and require a specific flag (
--confirm-destructive) to be executed. - Evidence:
lib.mjscontains theDESTRUCTIVE_KEYWORDSlist and theisDestructiveApifunction used byexecute.mjsto block sensitive operations by default. - [SAFE]: The skill modifies the project's
project.config.jsonto automatically ignore validation logs and artifacts. This is a standard development practice to prevent infinite build loops caused by file watchers. - Evidence:
validate.mjscontains theensureValidateIgnoreConfigfunction that updatespackOptions.ignoreandwatchOptions.ignorein the project configuration. - [SAFE]: The skill performs static analysis on project source code using a variety of regex-based rules (V001-V019) defined in
validate.mjsto ensure compliance with the WeChat Mini Program AI framework. - Evidence:
VALIDATE_RULES.mdandvalidate.mjsdetail the validation suite for WXML, WXSS, and JavaScript files within the skill subpackages.
Audit Metadata