tencent-edgeone-skill

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is authored by the service vendor (Tencent) and interacts exclusively with official Tencent Cloud APIs and domains (edgeone.ai, tencentcs.com). No malicious patterns or security bypass attempts were detected.
  • [COMMAND_EXECUTION]: The skill utilizes the official tccli tool for infrastructure management. Security 'red lines' in SKILL.md and individual module references (such as ip-threat-blacklist.md) explicitly mandate user confirmation and diff inspection for all operations that create, modify, or delete resources.
  • [EXTERNAL_DOWNLOADS]: Remote data retrieval is limited to fetching API documentation and best practices from cloudcache.tencentcs.com, a well-known service domain for Tencent Cloud's API metadata. It also provides standard instructions for installing and upgrading tccli via trusted package managers like pipx and Homebrew.
  • [DATA_EXFILTRATION]: No exfiltration or credential theft patterns were identified. The skill documentation (auth.md) specifically instructs the agent to avoid requesting SecretId or SecretKey from the user, instead directing them to use the browser-based OAuth login method (tccli auth login) to ensure secrets are handled securely by the CLI tool itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 03:05 PM
Security Audit — agent-trust-hub — tencent-edgeone-skill