qoder-cloud-agents-cn
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a legitimate management interface for the Qoder Cloud Agents platform. All referenced domains (qoder.com.cn, aliyun.com) are either vendor-owned or well-known trusted services for documentation. The skill explicitly provides security guidance, such as advising users to never share tokens in chat and to use least-privilege tokens for GitHub repository access.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines tools and workflows that allow agents to ingest data from potentially untrusted external sources, establishing a surface for indirect prompt injection attacks.\n
- Ingestion points: Session resources including external files (file_id), GitHub repositories, and Memory Store entries as described in shared/tools-and-resources.md.\n
- Boundary markers: The skill encourages the use of instructions and description fields to guide the agent's interaction with external resources, though it does not implement automated delimiters.\n
- Capability inventory: Managed agents possess significant capabilities within their sandbox environment, such as the Bash tool for command execution and Write/Edit for file system modifications.\n
- Sanitization: Content-level sanitization of external data is not performed by this management skill; the platform relies on the model's inherent safety guardrails during processing.
Audit Metadata