qoder-cloud-agents-cn

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a legitimate management interface for the Qoder Cloud Agents platform. All referenced domains (qoder.com.cn, aliyun.com) are either vendor-owned or well-known trusted services for documentation. The skill explicitly provides security guidance, such as advising users to never share tokens in chat and to use least-privilege tokens for GitHub repository access.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines tools and workflows that allow agents to ingest data from potentially untrusted external sources, establishing a surface for indirect prompt injection attacks.\n
  • Ingestion points: Session resources including external files (file_id), GitHub repositories, and Memory Store entries as described in shared/tools-and-resources.md.\n
  • Boundary markers: The skill encourages the use of instructions and description fields to guide the agent's interaction with external resources, though it does not implement automated delimiters.\n
  • Capability inventory: Managed agents possess significant capabilities within their sandbox environment, such as the Bash tool for command execution and Write/Edit for file system modifications.\n
  • Sanitization: Content-level sanitization of external data is not performed by this management skill; the platform relies on the model's inherent safety guardrails during processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:08 AM
Security Audit — agent-trust-hub — qoder-cloud-agents-cn