uniappx-uview-pro

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS] (SAFE): The skill references the uview-pro package through npm and the official DCloud plugin marketplace (Plugin ID: 24633). These are trusted and standard sources for dependencies in the UniApp ecosystem.\n- [DATA_EXFILTRATION] (SAFE): Network request examples (e.g., in uniappx-api.md) use non-sensitive placeholders and example domains like api.example.com. No access to sensitive user data, environment secrets, or credential files was detected.\n- [PROMPT_INJECTION] (SAFE): No instructions attempting to override agent behavior, bypass safety filters, or leak system prompts were found in any of the skill's markdown or metadata files.\n- [SAFE] (SAFE): The skill provides a surface for indirect prompt injection via external data ingestion (uni.request), which is a common characteristic of web and mobile application templates. However, the skill does not introduce specific vulnerabilities and the provided code follows standard development practices for UniAppX.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:12 PM