auth-web-cloudbase
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides integration guidance for the official
@cloudbase/js-sdk, which is a legitimate library provided by the vendor (tencentcloudbase). - [SAFE]: The skill includes proactive security advice, such as warning against using the deprecated
getLoginState()method which can return misleading authentication states, and recommendinggetSession()for reliable route guards. - [SAFE]: All external URLs referenced, such as
tcb.cloud.tencent.com, are official management console domains belonging to the vendor. - [SAFE]: The
accessKeymentioned in the quick start guide is correctly identified as a publishable (public) key for SDK initialization, not a sensitive secret key. - [SAFE]: The skill correctly instructs the agent to use local sibling skills for environment configuration rather than fetching remote resources, adhering to the principle of least privilege and local context.
Audit Metadata