Skills miniprogram-development
๐Ÿ“ฆ

miniprogram-development

v2.23.8 Content revision r1 High Risk โš™๏ธ External commands๐ŸŒ Network access๐Ÿ“ Filesystem access

Build WeChat Mini Programs with CloudBase

WeChat Mini Program work requires platform-specific structure, preview, and CloudBase decisions. This skill guides setup, debugging, release checks, and CloudBase integration.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "miniprogram-development" from https://skillstore.io/skills/tencentcloudbase-miniprogram-development.md and its manifest at https://skillstore.io/api/skills/tencentcloudbase-miniprogram-development/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "miniprogram-development". Review a Mini Program tab bar that has unwanted icon spacing.

Expected outcome:

  • Recommends a text-only custom tabBar when icons are not required.
  • Explains which layout properties remove blank icon space.
  • Lists files that need coordinated changes.

Using "miniprogram-development". Plan CloudBase support for user-generated image uploads.

Expected outcome:

  • Separates client upload steps from permission-sensitive server logic.
  • Calls out environment selection and storage permission checks.
  • Warns against hard-coded environment guesses.

Using "miniprogram-development". Prepare a project for real-device preview.

Expected outcome:

  • Checks appid, miniprogramRoot, page registration, and local assets.
  • Prefers WeChat Developer Tools for simulator and device testing.
  • Uses miniprogram-ci only when DevTools is unavailable.

Security Audit

High Risk
v2 โ€ข 7/9/2026 Open versioned report

Most static command findings are false positives caused by Markdown code spans and fenced examples. Confirmed issues are the mutable external instruction URLs and parent-directory references to sibling skills outside the package. No prompt injection language was found in the reviewed files.

3
Files scanned
423
Lines analyzed
12
Review items
0
False positives ignored

Confirmed security concerns (1)

High
Unpinned External Instruction References
The skill tells agents to use raw external skill and protocol URLs from a main branch. Future remote changes could alter agent instructions after this package is reviewed.
The referenced URLs point to raw external instruction files on a mutable branch. The skill explicitly presents them as entries or fallbacks for agent use.
Capability review items (12)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
Path traversal sequence
- CloudBase auth -> `../auth-wechat/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/
The skill directs agents to read sibling paths using ../ outside the packaged skill directory. The targets are fixed, but they cross the audited package boundary.
High
Path traversal sequence
- CloudBase document DB -> `../no-sql-wx-mp-sdk/SKILL.md` (standalone fallback: `https://cnb.cool/te
The skill directs agents to read sibling paths using ../ outside the packaged skill directory. The targets are fixed, but they cross the audited package boundary.
High
Path traversal sequence
- Mini Program WeChat Pay or Integration Center generated payment functions -> `../cloudbase-wechat-
The skill directs agents to read sibling paths using ../ outside the packaged skill directory. The targets are fixed, but they cross the audited package boundary.
High
Path traversal sequence
- UI generation -> `../ui-design/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/clo
The skill directs agents to read sibling paths using ../ outside the packaged skill directory. The targets are fixed, but they cross the audited package boundary.
Low
Hardcoded URL
- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk
The URL is documentation-like, but it points to mutable external skill or protocol content. Agents may import unreviewed instructions from that remote source.
Low
Hardcoded URL
- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai
The URL is documentation-like, but it points to mutable external skill or protocol content. Agents may import unreviewed instructions from that remote source.
Low
Hardcoded URL
- Change Safety Protocol: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/
The URL is documentation-like, but it points to mutable external skill or protocol content. Agents may import unreviewed instructions from that remote source.
Low
Hardcoded URL
- Deployment Gate: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/
The URL is documentation-like, but it points to mutable external skill or protocol content. Agents may import unreviewed instructions from that remote source.
Low
Hardcoded URL
- CloudBase auth -> `../auth-wechat/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/
The URL is documentation-like, but it points to mutable external skill or protocol content. Agents may import unreviewed instructions from that remote source.
Low
Hardcoded URL
- CloudBase document DB -> `../no-sql-wx-mp-sdk/SKILL.md` (standalone fallback: `https://cnb.cool/te
The URL is documentation-like, but it points to mutable external skill or protocol content. Agents may import unreviewed instructions from that remote source.
Low
Hardcoded URL
- Mini Program WeChat Pay or Integration Center generated payment functions -> `../cloudbase-wechat-
The URL is documentation-like, but it points to mutable external skill or protocol content. Agents may import unreviewed instructions from that remote source.
Low
Hardcoded URL
- UI generation -> `../ui-design/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/clo
The URL is documentation-like, but it points to mutable external skill or protocol content. Agents may import unreviewed instructions from that remote source.
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/tencentcloudbase-miniprogram-development/audits/2?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/tencentcloudbase-miniprogram-development/security.svg)](https://skillstore.io/skills/tencentcloudbase-miniprogram-development?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/tencentcloudbase-miniprogram-development?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/tencentcloudbase-miniprogram-development/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/tencentcloudbase-miniprogram-development.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

tencentcloudbase. (2026). miniprogram-development security audit report (audit version 2) [Author version 2.23.8]. Skillstore. https://skillstore.io/skills/tencentcloudbase-miniprogram-development/audits/2

BibTeX citation

@techreport{tencentcloudbase-tencentcloudbase-miniprogram-development-2026, author = {tencentcloudbase}, title = {miniprogram-development security audit report (audit version 2)}, institution = {Skillstore}, year = {2026}, number = {2}, url = {https://skillstore.io/skills/tencentcloudbase-miniprogram-development/audits/2}, note = {Author version 2.23.8} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "miniprogram-development security audit report (audit version 2)" version: "2.23.8" type: report authors: - name: "tencentcloudbase" date-released: "2026-07-09" url: "https://skillstore.io/skills/tencentcloudbase-miniprogram-development/audits/2" identifiers: - type: other value: "skillstore:tencentcloudbase-miniprogram-development:audit:2" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
41
Architecture
100
Maintainability
87
Content
65
Community
91
Spec Compliance

What You Can Build

Create Mini Program Pages

Plan page files, component structure, routing, and required configuration for a new feature.

Review Preview Readiness

Check project configuration, appid, miniprogramRoot, assets, and preview workflow before device testing.

Add CloudBase Integration

Apply wx.cloud patterns for environment setup, identity, database access, storage, and cloud functions.

Try These Prompts

Create a Basic Page
Create a WeChat Mini Program page for [feature]. Include required page files and explain where each file belongs.
Review Project Configuration
Review this Mini Program project configuration for preview readiness. Check appid, miniprogramRoot, page registration, and asset paths.
Add CloudBase Data Flow
Design a CloudBase data flow for [feature]. Use wx.cloud correctly and separate client-safe writes from privileged cloud function work.
Prepare Release Workflow
Prepare this Mini Program for preview or upload. Identify required checks for DevTools, real-device testing, miniprogram-ci, and release gates.

Best Practices

  • Confirm the configured Mini Program root before editing page files.
  • Use CloudBase rules only when the project clearly uses CloudBase.
  • Complete preview and release checks before upload or publishing.

Avoid

  • Do not copy Web authentication patterns into Mini Programs.
  • Do not create icon-based tab bars when text-only tabs meet the requirement.
  • Do not publish without checking appid, assets, and project configuration.

Frequently Asked Questions

What projects does this skill support?
It supports WeChat Mini Program projects, especially projects that need structure, preview, release, or CloudBase guidance.
Does it require CloudBase?
No. It applies CloudBase rules only when the user or codebase shows CloudBase usage.
Can it help with WeChat Developer Tools?
Yes. It guides simulator, panel debugging, preview, and real-device validation workflows.
Can it use miniprogram-ci?
Yes. It treats miniprogram-ci as a fallback for preview, upload, and build workflows.
Does it cover WeChat Pay?
Only at the routing level. Payment callbacks, refunds, and OAuth details are delegated to another skill.
Which AI tools can use it?
The report lists support for Claude, Codex, and Claude Code.

Developer Details

License

MIT

Author version

v2.23.8

Skillstore revision

r1

Ref

24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec

Maintenance freshness

7/18/2026

Usage

1 downloads ยท 0 views

File structure

๐Ÿ“ references/

๐Ÿ“„ cloudbase-integration.md

๐Ÿ“„ pitfalls.md

๐Ÿ“„ SKILL.md

More from tencentcloudbase

View all
View all