wechatpay-payment-integration

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill performs self-updates by executing scripts/wechatpay-resource-sync.py, which downloads and extracts a code bundle from the official WeChat CDN (wx.gtimg.com) to the skill directory. Instructions in SKILL.md require the agent to run this script as a mandatory initialization step.
  • [EXTERNAL_DOWNLOADS]: The skill is configured to download documentation assets and software updates from official vendor domains, including wx.gtimg.com and pay.weixin.qq.com.
  • [COMMAND_EXECUTION]: The skill utilizes a specialized CLI tool (wechatpay-dev-cli) for knowledge retrieval and provides bash/PowerShell scripts for the user to run locally. These scripts handle sensitive P12 certificates and generate cryptographic signatures required for APIv3 troubleshooting.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external official documentation pages to answer user queries, which creates a potential surface for instructions embedded in external vendor content to influence agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 06:05 AM
Security Audit — agent-trust-hub — wechatpay-payment-integration