cloud-storage-web

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as an instructional guide for the @cloudbase/js-sdk library, which is a legitimate package provided by the vendor (tencentcloudbase).
  • [SAFE]: The instructions emphasize security best practices, including the mandatory configuration of PostgreSQL Row Level Security (RLS) on storage tables (storage.objects) to prevent unauthorized access.
  • [SAFE]: The skill explicitly forbids fetching remote markdown or protocol files into the agent context, which is a proactive measure against Server-Side Request Forgery (SSRF) and unauthorized data ingestion.
  • [SAFE]: The usage of environment management tools like envDomainManagement and managePgDatabase is scoped to legitimate configuration tasks (CORS whitelisting and RLS policy application) and includes safeguards like user confirmation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — cloud-storage-web