auth-tool-cloudbase

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill includes explicit security warnings regarding the trade-offs of enabling anonymous login and advises on proper session management and access control (e.g., AuthGuard and RLS). It also explicitly instructs the agent not to fetch remote skill content via HTTP, which is a positive security boundary.
  • [CREDENTIALS_UNSAFE]: The skill describes the management of sensitive credentials such as API keys, OAuth secrets, and SMTP configuration. However, it correctly utilizes placeholders (e.g., AppID, Client Secret, AccountPassword) rather than hardcoding any actual secrets.
  • [COMMAND_EXECUTION]: The skill guides the agent in using administrative MCP tools like manageAppAuth, queryAppAuth, and callCloudApi to modify CloudBase environment settings. These tools are used as intended for platform management.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it ingests user-supplied environment IDs and configuration data to generate API calls.
  • Ingestion points: User-provided environment IDs (env), provider credentials (e.g., AppID, ClientSecret), and login strategy flags (e.g., phone: true).
  • Boundary markers: The instructions reference a Change Safety Protocol and emphasize using structured JSON for MCP tool communication.
  • Capability inventory: Powerful management tools including manageAppAuth, queryAppAuth, and callCloudApi are available to the agent.
  • Sanitization: The skill relies on structured tool calls and platform-side validation rather than explicit string sanitization in the prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — auth-tool-cloudbase