wind-mcp-skill

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts exclusively with the vendor's verified domains (mcp.wind.com.cn and aimarket.wind.com.cn) for data retrieval and developer portal access.
  • [SAFE]: Credential management is handled through local configuration files or environment variables, which is a standard and secure practice for CLI-based tools.
  • [SAFE]: Subprocess spawning is restricted to benign utility tasks, such as opening the official developer portal in the system's default browser or executing internal version-check scripts.
  • [SAFE]: The update mechanism queries trusted repository APIs (GitHub and Gitee) to compare commit hashes, ensuring that users are notified of new versions without the execution of untrusted remote code.
  • [SAFE]: No patterns of prompt injection, obfuscation, or unauthorized data exfiltration were identified during the security audit.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 01:36 AM
Security Audit — agent-trust-hub — wind-mcp-skill