wechat-miniapp-review

wechat-miniapp-review is a skill for Claude Code, Codex from guyulong/cn-agent-skills. It costs 19 tokens per session (423 once invoked), scanned A, original, MIT.

A review checklist for WeChat Mini Programs, small apps that run inside WeChat. It covers configuration, page structure, styling, logic, performance, security, and platform compliance.

In plain words
What is it for?
Use it to inspect Mini Program files, verify WXML and WXSS usage, review network and page lifecycle code, check image and list performance, and look for unsafe handling of secrets or user data.
Why use it?
It helps find problems that can cause incorrect pages, slow behavior, security risks, or rejection under WeChat rules. The checks include failed requests, cleanup, permissions, data size, privacy, and payments.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it to inspect Mini Program files, verify WXML and WXSS usage, review network and page lifecycle code, check image and list performance, and look for unsafe handling of secrets or user data.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/guyulong/cn-agent-skills/wechat-miniapp-review
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add guyulong/cn-agent-skills --skill wechat-miniapp-review
Clone the repo
git clone --depth 1 https://github.com/guyulong/cn-agent-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for wechat-miniapp-review

README.md
[![agentmods](https://agentmods.dev/badge/skills/guyulong/cn-agent-skills/wechat-miniapp-review/github.svg)](https://agentmods.dev/skills/guyulong/cn-agent-skills/wechat-miniapp-review)
Your own site
<a href="https://agentmods.dev/skills/guyulong/cn-agent-skills/wechat-miniapp-review"><img src="https://agentmods.dev/badge/skills/guyulong/cn-agent-skills/wechat-miniapp-review/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for wechat-miniapp-review

Your own site · 80×15
<a href="https://agentmods.dev/skills/guyulong/cn-agent-skills/wechat-miniapp-review"><img src="https://agentmods.dev/badge/skills/guyulong/cn-agent-skills/wechat-miniapp-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 19 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 423 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00019 $0.00423
Opus 5 $0.00010 $0.00211
Sonnet 5 $0.00004 $0.00085
Haiku 4.5 $0.00002 $0.00042

Measured 11d ago against content hash b2a1698b5bb3, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

wechat-miniapp-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/wechat-miniapp-review/SKILL.md · 55 lines

What it actually says

微信小程序代码审查

使用场景

审查微信小程序代码,确保符合微信平台规范和最佳实践。

检查清单

1. 配置文件检查

  • app.json 页面路径是否正确
  • project.config.json appid是否配置
  • sitemap.json 是否配置索引规则

2. 页面结构检查

  • WXML 标签是否正确闭合
  • 使用 <view> 而非 <div>
  • 使用 <text> 而非 <span>
  • <image> 必须设置 mode 属性

3. 样式检查

  • rpx 单位使用是否正确
  • 全局样式是否在 app.wxss
  • 避免使用 * 选择器

4. 逻辑检查

  • wx.request 是否处理了失败回调
  • 是否在 onUnload 中清理定时器
  • 是否处理了用户拒绝授权的情况
  • setData 数据量是否过大(应<256KB)

5. 性能检查

  • 图片是否压缩
  • 是否使用了分包加载
  • 长列表是否使用虚拟列表
  • 避免在 onPageScroll 中频繁 setData

6. 安全检查

  • 敏感信息不存储在本地
  • 接口请求使用 HTTPS
  • 用户输入做了XSS过滤
  • 不在前端存放密钥

7. 合规检查

  • 隐私协议是否配置
  • 用户信息获取是否有说明
  • 支付功能是否有资质
  • 内容是否符合平台规范
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 11d ago First seen · 55 lines · 19 tokens per session scan A b2a1698b5bb3

Subscribe to this mod's changes

wechat-miniapp-review is a skill published in the GitHub repository guyulong/cn-agent-skills (3 stars, last pushed 3mo ago), licensed MIT. It adds 19 tokens to every session and 423 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

app-store-review

Evaluates code against Apple's App Store Review Guidelines. Use this skill when reviewing iOS, macOS, tvOS, watchOS, or visionOS app code (Swift, Objective-C, React Native, or Expo) to identify potential App Store rejection issues before submission. Triggers on tasks involving app review preparation, compliance…

jacklandrin/OnlySwitch · 76 tokens

swift-concurrency-pro

Reviews Swift code for concurrency correctness, modern API usage, and common async/await pitfalls. Use when reading, writing, or reviewing Swift concurrency code.

jacklandrin/OnlySwitch · 35 tokens

swiftui-pro

Comprehensively reviews SwiftUI code for best practices on modern APIs, maintainability, and performance. Use when reading, writing, or reviewing SwiftUI projects.

jacklandrin/OnlySwitch · 36 tokens

axiom-audit-camera

Use this agent to scan Swift code for camera, video, and audio capture issues including deprecated APIs, missing interruption handlers, threading violations, and permission anti-patterns.

CharlesWiltgen/Axiom · 39 tokens

mobile-onboarding

A visual template showing three mobile-app onboarding screens side by side: a splash screen, a feature introduction, and sign-in.

nexu-io/html-anything · 18 tokens

mobile-platform-offline-validate

Review a Lightning Web Component for mobile offline compatibility — the Komaci offline static analyzer that pre-primes the data graph for Salesforce Mobile App Plus and Field Service Mobile App. Produces a finding list with code-level fixes covering inline GraphQL queries in @wire configurations, modern lwc:if /…

forcedotcom/sf-skills · 207 tokens