cloudbase-agent

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill utilizes strict instructional markers in py/agent-deployment.md (e.g., "AI: You MUST execute Steps 1→2→3→4 in order") to ensure the agent follows a critical deployment workflow. These instructions are functional and intended for reliable automation rather than bypassing safety guardrails.
  • [COMMAND_EXECUTION]: The py/agent-deployment.md file includes shell scripts and Python code snippets (executed via python3.10 -c) to manage build environments, install dependencies, and verify the integrity of package imports before deployment. These are standard development operations within the context of an SDK deployment pipeline.
  • [EXTERNAL_DOWNLOADS]: The documentation directs the installation of official SDK packages (e.g., cloudbase-agent-server, cloudbase-agent-langgraph) from the tencentcloudbase vendor repository via standard package registries like PyPI and NPM. These resources are consistent with the skill's stated purpose and author.
  • [CREDENTIALS_UNSAFE]: The documentation includes placeholder values for API keys and secrets (such as "sk-1234567890" and "your-secret-key") in files like py/adapter-coze.md and py/authentication.md. These are used as examples for developer configuration and do not represent leaked credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — cloudbase-agent