auth-nodejs-cloudbase
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for identifying callers and querying user profiles based on externally supplied identifiers.
- Ingestion points: The
uidandplatformIdparameters (such as phone numbers or emails) used ingetEndUserInfoandqueryUserInfomethods (SKILL.md). - Boundary markers: There are no specific instructions to use delimiters or ignore embedded instructions within these data points.
- Capability inventory: The skill uses the
@cloudbase/node-sdkto make network requests to CloudBase authentication APIs. - Sanitization: The instructions do not describe sanitization or validation logic for the input identifiers before they are passed to the SDK.
- [COMMAND_EXECUTION]: The skill instructs the agent to perform package installation at runtime to ensure the environment is ready.
- Evidence: The agent is told to "Install the latest
@cloudbase/node-sdkfrom npm if it is not already available" (SKILL.md). - [DATA_EXFILTRATION]: The skill provides code to load a sensitive configuration file containing private keys.
- Evidence: The documentation demonstrates loading
tcb_custom_login.jsonfrom the local file system usingrequire(path.join(__dirname, "tcb_custom_login.json"))(SKILL.md). - Context: This is part of the standard 'Custom Login' setup and the skill includes explicit warnings to keep this file secret and never expose it to client-side code.
Audit Metadata