auth-nodejs-cloudbase

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for identifying callers and querying user profiles based on externally supplied identifiers.
  • Ingestion points: The uid and platformId parameters (such as phone numbers or emails) used in getEndUserInfo and queryUserInfo methods (SKILL.md).
  • Boundary markers: There are no specific instructions to use delimiters or ignore embedded instructions within these data points.
  • Capability inventory: The skill uses the @cloudbase/node-sdk to make network requests to CloudBase authentication APIs.
  • Sanitization: The instructions do not describe sanitization or validation logic for the input identifiers before they are passed to the SDK.
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform package installation at runtime to ensure the environment is ready.
  • Evidence: The agent is told to "Install the latest @cloudbase/node-sdk from npm if it is not already available" (SKILL.md).
  • [DATA_EXFILTRATION]: The skill provides code to load a sensitive configuration file containing private keys.
  • Evidence: The documentation demonstrates loading tcb_custom_login.json from the local file system using require(path.join(__dirname, "tcb_custom_login.json")) (SKILL.md).
  • Context: This is part of the standard 'Custom Login' setup and the skill includes explicit warnings to keep this file secret and never expose it to client-side code.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — auth-nodejs-cloudbase