cloudbase-agent
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes strict instructional markers in py/agent-deployment.md (e.g., "AI: You MUST execute Steps 1→2→3→4 in order") to ensure the agent follows a critical deployment workflow. These instructions are functional and intended for reliable automation rather than bypassing safety guardrails.
- [COMMAND_EXECUTION]: The py/agent-deployment.md file includes shell scripts and Python code snippets (executed via python3.10 -c) to manage build environments, install dependencies, and verify the integrity of package imports before deployment. These are standard development operations within the context of an SDK deployment pipeline.
- [EXTERNAL_DOWNLOADS]: The documentation directs the installation of official SDK packages (e.g., cloudbase-agent-server, cloudbase-agent-langgraph) from the tencentcloudbase vendor repository via standard package registries like PyPI and NPM. These resources are consistent with the skill's stated purpose and author.
- [CREDENTIALS_UNSAFE]: The documentation includes placeholder values for API keys and secrets (such as "sk-1234567890" and "your-secret-key") in files like py/adapter-coze.md and py/authentication.md. These are used as examples for developer configuration and do not represent leaked credentials.
Audit Metadata