cloudbase-code-review

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed as a security and best-practice validator for CloudBase implementations. Its primary function is to provide the agent with a set of rules (e.g., proper authentication guards, RLS configuration, and credential leak prevention) to review user-provided code.
  • [COMMAND_EXECUTION]: The skill includes a Node.js linting script located in references/lint-rules/README.md. The instructions in SKILL.md and the README explicitly specify that the script is not shipped as an executable and must be manually reviewed and copied by the user into a local file (cloudbase-lint.mjs) before execution. The script itself uses only standard Node.js modules (node:fs, node:path) and does not perform network operations.
  • [DATA_EXFILTRATION]: While the provided lint script reads local project files using readFileSync, it only processes the content to identify regex-based patterns and logs the results to the console. It contains no logic for sending data to external endpoints.
  • [INDIRECT_PROMPT_INJECTION]: As a code-review skill, it naturally processes external, untrusted code. This creates a surface for indirect prompt injection (e.g., code containing instructions to deceive the reviewer). However, the skill provides a structured rule-based framework for analysis, which guides the agent to look for specific architectural patterns rather than following instructions within the reviewed code.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — cloudbase-code-review