cloudbase-cli
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous examples of
tcbCLI commands for managing cloud functions, databases, storage, and hosting. These are legitimate administrative operations used for cloud resource management. - [EXTERNAL_DOWNLOADS]: The documentation recommends the installation of the
@cloudbase/clipackage. This is a recognized tool belonging to the skill's author (tencentcloudbase) and is necessary for the skill's functionality. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided data (such as SQL queries or configuration JSON) and interpolate it into CLI commands. The instructions mitigate injection risks by mandating the use of the
--dry-runflag and requiring explicit user confirmation before executing any destructive operations. - [SAFE]: The skill includes explicit security warnings, advising users not to hardcode credentials and to use environment variables instead. It also contains instructions to prevent the automatic fetching of remote content into the agent context.
Audit Metadata