In theory this is enough to prove it's genuine because they are supposed to be tamper-proof, i.e even if you buy indirectly or it's intercepted in transit.
The only thing I can see this failing to detect is an intermediate layer that intercepts USB and has access to the physical button... e.g If an attacker embedded a genuine small form-factor key into a larger package that mimics a larger form factor. This would be useful to an attacker which could get a target to trust the key, believe it's genuine and start associating it with services, and then be able to remotely activate it once they have gained the users trust... still a tough challenge to pack all of that with wifi etc into a small enough package with a micro yubikey or something inside.
I don't think this is a very realistic possibility currently, but if you are concerned, you could simply buy the smallest possible yubikey form factor.