cloudbase-code-review
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed as a security and best-practice validator for CloudBase implementations. Its primary function is to provide the agent with a set of rules (e.g., proper authentication guards, RLS configuration, and credential leak prevention) to review user-provided code.
- [COMMAND_EXECUTION]: The skill includes a Node.js linting script located in
references/lint-rules/README.md. The instructions inSKILL.mdand the README explicitly specify that the script is not shipped as an executable and must be manually reviewed and copied by the user into a local file (cloudbase-lint.mjs) before execution. The script itself uses only standard Node.js modules (node:fs,node:path) and does not perform network operations. - [DATA_EXFILTRATION]: While the provided lint script reads local project files using
readFileSync, it only processes the content to identify regex-based patterns and logs the results to the console. It contains no logic for sending data to external endpoints. - [INDIRECT_PROMPT_INJECTION]: As a code-review skill, it naturally processes external, untrusted code. This creates a surface for indirect prompt injection (e.g., code containing instructions to deceive the reviewer). However, the skill provides a structured rule-based framework for analysis, which guides the agent to look for specific architectural patterns rather than following instructions within the reviewed code.
Audit Metadata