cloud-storage-web
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as an instructional guide for the
@cloudbase/js-sdklibrary, which is a legitimate package provided by the vendor (tencentcloudbase). - [SAFE]: The instructions emphasize security best practices, including the mandatory configuration of PostgreSQL Row Level Security (RLS) on storage tables (
storage.objects) to prevent unauthorized access. - [SAFE]: The skill explicitly forbids fetching remote markdown or protocol files into the agent context, which is a proactive measure against Server-Side Request Forgery (SSRF) and unauthorized data ingestion.
- [SAFE]: The usage of environment management tools like
envDomainManagementandmanagePgDatabaseis scoped to legitimate configuration tasks (CORS whitelisting and RLS policy application) and includes safeguards like user confirmation.
Audit Metadata