Security audit
cloudbase-wechat-integration
Security checks across malware telemetry and agentic risk
Overview
This is a documentation-only CloudBase WeChat payment and OAuth skill that gives scoped safety guidance rather than installing code or collecting secrets.
Install only if you want Codex guidance for CloudBase WeChat payment or Official Account OAuth work. Because the domain involves real payments and identity data, keep merchant keys, AppSecrets, certificates, and APIv3 keys in the CloudBase console, review generated payment/callback code carefully, and test with sandbox or low-value transactions before production use.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
