wxmini-security-audit

Security Community v1.0.0
Interpretation is structured for decision-making; original keeps the upstream SKILL.md unchanged.

Decide Fit First

  • Core job: 微信小程序全自动安全审计 Skill。使用 Agent Teams 编排多个 Agent,分阶段完成从反编译到报告生成的全流程静态安全分析。 覆盖维度:敏感信息泄露、API接口提取、加解密算法分析、漏洞分析。 当用户请求分析微信小程序时触发。 从用户输入中…
  • Best fit: Use it when the task has reusable inputs, steps, and validation criteria rather than a one-off answer.
  • Avoid forcing it: If the source lacks commands, platform support, or external-service evidence, keep those fields unknown instead of guessing.

Design Intent

  • Structure: The skill is organized around “核心原则(所有 Agent 必须遵守)”, “编排铁律(Orchestrator 禁令,硬性约束)”, “描述”, “触发方式”, showing how the author expects the agent to judge fit, collect context, and produce verifiable output.
  • Trigger evidence: Prioritize the author’s wording around when to use it, what context to collect, and what output shape to produce.
  • Evidence boundary: Author text states facts, repository files prove commands and paths, and Fluxly only adds fit, limits, and usage judgment.

How To Use It

  • Inputs: Provide target material, scope, expected result, forbidden changes, and validation method.
  • Invocation: Name wxmini-security-audit directly; if the source includes slash commands, start with the command and then add task context.
  • Validation: Start small and check whether the result follows “核心原则(所有 Agent 必须遵守) / 编排铁律(Orchestrator 禁令,硬性约束) / 描述” before expanding.

Boundaries And Review

  • Dependencies: It usually needs no extra API key, so start with a small validation task.
  • Permissions: Declared permissions include read / write; ask the agent to state file, command, and rollback boundaries before acting.
  • Quality bar: A useful result names the deliverable, evidence, and next action. Generic prose means the task needs tighter context.
Fluxly profile Author and license come from source; runtime, permissions, and network are Fluxly detections or estimates
Fluxly category
Security · security · wechat · miniprogram
Author-declared agents
No explicit declaration found; this is not inferred or tested compatibility
Static check
98 / 100 · heuristic scan, not runtime safety proof
Author / version / license
@sssmmmwww · v1.0.0 · no license declared
Fluxly token estimate
Moderate
Fluxly setup estimate
Guided setup
External API key
No requirement detected
Detected OS requirements
macOS · Linux · Windows
Runtime requirements
Python
Detected file/system behavior
  • Read-only
  • Write / modify
Detected network behavior
External requests
Install commands
None (reference only)

Profile is derived at build time from SKILL.md and install vectors. Subject to drift from author intent.

Output preview wxmini-security-audit.preview
The current SKILL.md does not define a fixed output example.

Discussion

Powered by GitHub Discussions. Sign in with GitHub to comment, react, or subscribe.