wechatpay-payscore
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected in the skill's instructions or code references.
- [COMMAND_EXECUTION]: The skill contains logic for the agent to guide users through integration tasks, but it explicitly forbids the agent from using tools like
write_to_fileorreplace_in_fileto modify the user's project directly. - [DATA_EXFILTRATION]: All code examples use standard WeChat Pay domains (e.g., api.mch.weixin.qq.com) and utilize placeholders (e.g., 'xxx', '19xxxxxxxx') for sensitive credentials like API keys and merchant IDs.
- [PROMPT_INJECTION]: The skill uses role-playing instructions ('金融支付系统技术专家') to set a technical context for quality assessment, which is a benign use of persona to improve task accuracy and does not attempt to bypass core safety filters.
- [EXTERNAL_DOWNLOADS]: The skill references standard libraries such as OkHttp, Gson, and Bouncy Castle, which are well-known and trusted dependencies in the developer community.
Audit Metadata