wind-mcp-skill
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill interacts exclusively with the vendor's verified domains (mcp.wind.com.cn and aimarket.wind.com.cn) for data retrieval and developer portal access.
- [SAFE]: Credential management is handled through local configuration files or environment variables, which is a standard and secure practice for CLI-based tools.
- [SAFE]: Subprocess spawning is restricted to benign utility tasks, such as opening the official developer portal in the system's default browser or executing internal version-check scripts.
- [SAFE]: The update mechanism queries trusted repository APIs (GitHub and Gitee) to compare commit hashes, ensuring that users are notified of new versions without the execution of untrusted remote code.
- [SAFE]: No patterns of prompt injection, obfuscation, or unauthorized data exfiltration were identified during the security audit.
Audit Metadata