AI Agent Hub
Back to skills
Mini Program Security Scanning icon

Mini Program Security Scanning

IT Ops & Security Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please follow https://skillhub.cn/install/skillhub.md to install @user_4a86686d/mini-program-sast into your AI assistant.

About this skill

Problem Addressed

WeChat mini-program front-end code often ships as local .wxapkg binary packages inside the WeChat client cache. Sensitive front-end risks are hard to inspect manually, such as plaintext storage via wx.setStorageSync, persisted wx.login code, openId passed through URL query parameters, hardcoded credentials, and leftover Mock flags. This skill performs front-end static security scanning on a mini-program that has already been opened on a Mac or Windows WeChat desktop client, producing an audit report that can be used for remediation tracking.

How It Works

  • Locate cached packages: uses the AppID to find the macOS or Windows WeChat cache path, handles official and App Store layouts, and falls back to broadcast search when needed.
  • Extract readable content: extracts readable strings from __APP__.wxapkg and subpackages, supporting standard V1MMWX and WMPF formats.
  • Pattern-match findings: applies mini-program-specific rules to detect credential storage, persisted login codes, openId in URL parameters, hardcoded AppSecret, MD5 payment signing, non-HTTPS requests, debug leftovers, and similar issues.
  • Generate a graded report: outputs a structured HTML report with executive summary, target details, risk ratings, detection coverage, remediation guidance, and audit limitations; it can be printed to PDF from a browser.

Boundaries and Caveats

The skill only scans locally cached mini-program front-end assets. It does not access back-end services, perform penetration testing, or bypass WeChat transport-layer encryption. If the mini-program was not opened, the cache was cleared, the AppID is wrong, or the package uses strong code protection, coverage may be limited. It is suitable for front-end security triage and compliance self-checks, not as a replacement for WeChat's official security scanning service or full source-code audit.

Use Cases

  • A security engineer checks a cached mini-program package by AppID for plaintext credentials or hardcoded secrets.
  • A front-end lead audits pre-release mini-program code for Mock leftovers, debug code, and unsafe URL navigation.
  • A compliance specialist exports mini-program front-end risk findings to PDF for remediation or compliance materials.
  • An ops engineer locates local wxapkg packages after opening the mini-program and generates a graded audit report.

Best For

  • Mini-program security engineer: quickly check local cache for plaintext credentials, login-code leaks, and hardcoded secrets using the AppID.
  • Front-end lead: self-check pre-release issues such as Mock leftovers, non-HTTPS requests, and unsafe navigation.
  • Compliance specialist: compile mini-program front-end scan findings into a PDF for security remediation or compliance evidence.
  • Ops engineer: identify local wxapkg packages and produce a graded audit report on macOS or Windows.