auth-tool-cloudbase
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill includes explicit security warnings regarding the trade-offs of enabling anonymous login and advises on proper session management and access control (e.g., AuthGuard and RLS). It also explicitly instructs the agent not to fetch remote skill content via HTTP, which is a positive security boundary.
- [CREDENTIALS_UNSAFE]: The skill describes the management of sensitive credentials such as API keys, OAuth secrets, and SMTP configuration. However, it correctly utilizes placeholders (e.g.,
AppID,Client Secret,AccountPassword) rather than hardcoding any actual secrets. - [COMMAND_EXECUTION]: The skill guides the agent in using administrative MCP tools like
manageAppAuth,queryAppAuth, andcallCloudApito modify CloudBase environment settings. These tools are used as intended for platform management. - [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it ingests user-supplied environment IDs and configuration data to generate API calls.
- Ingestion points: User-provided environment IDs (
env), provider credentials (e.g.,AppID,ClientSecret), and login strategy flags (e.g.,phone: true). - Boundary markers: The instructions reference a
Change Safety Protocoland emphasize using structured JSON for MCP tool communication. - Capability inventory: Powerful management tools including
manageAppAuth,queryAppAuth, andcallCloudApiare available to the agent. - Sanitization: The skill relies on structured tool calls and platform-side validation rather than explicit string sanitization in the prompt.
Audit Metadata