Mini Program Security Scanning
Paste the following prompt into your AI chat to install this skill:
Please follow https://skillhub.cn/install/skillhub.md to install @user_4a86686d/mini-program-sast into your AI assistant.
About this skill
Problem Addressed
WeChat mini-program front-end code often ships as local .wxapkg binary packages inside the WeChat client cache. Sensitive front-end risks are hard to inspect manually, such as plaintext storage via wx.setStorageSync, persisted wx.login code, openId passed through URL query parameters, hardcoded credentials, and leftover Mock flags. This skill performs front-end static security scanning on a mini-program that has already been opened on a Mac or Windows WeChat desktop client, producing an audit report that can be used for remediation tracking.
How It Works
- Locate cached packages: uses the
AppIDto find the macOS or Windows WeChat cache path, handles official and App Store layouts, and falls back to broadcast search when needed. - Extract readable content: extracts readable strings from
__APP__.wxapkgand subpackages, supporting standardV1MMWXand WMPF formats. - Pattern-match findings: applies mini-program-specific rules to detect credential storage, persisted login codes,
openIdin URL parameters, hardcodedAppSecret,MD5payment signing, non-HTTPS requests, debug leftovers, and similar issues. - Generate a graded report: outputs a structured HTML report with executive summary, target details, risk ratings, detection coverage, remediation guidance, and audit limitations; it can be printed to PDF from a browser.
Boundaries and Caveats
The skill only scans locally cached mini-program front-end assets. It does not access back-end services, perform penetration testing, or bypass WeChat transport-layer encryption. If the mini-program was not opened, the cache was cleared, the AppID is wrong, or the package uses strong code protection, coverage may be limited. It is suitable for front-end security triage and compliance self-checks, not as a replacement for WeChat's official security scanning service or full source-code audit.
Use Cases
- A security engineer checks a cached mini-program package by AppID for plaintext credentials or hardcoded secrets.
- A front-end lead audits pre-release mini-program code for Mock leftovers, debug code, and unsafe URL navigation.
- A compliance specialist exports mini-program front-end risk findings to PDF for remediation or compliance materials.
- An ops engineer locates local wxapkg packages after opening the mini-program and generates a graded audit report.
Best For
- Mini-program security engineer: quickly check local cache for plaintext credentials, login-code leaks, and hardcoded secrets using the AppID.
- Front-end lead: self-check pre-release issues such as Mock leftovers, non-HTTPS requests, and unsafe navigation.
- Compliance specialist: compile mini-program front-end scan findings into a PDF for security remediation or compliance evidence.
- Ops engineer: identify local wxapkg packages and produce a graded audit report on macOS or Windows.
Related Skills
Detects child climbing, leaning out, or gripping window/balcony edges from surveillance video and outputs tiered alerts with historical reports.
A pre-release security auditor for Skills that statically checks injection, credentials, SSRF, CVEs, and permissions, with scored reports.
For independent developers, automates Git weekly reports, prioritized bug tickets, and project health checks into shareable Markdown.
Scan Windows caches, temporary files, and junk files, show space usage and risk levels, and clean selected items to free disk space.