cloudbase-platform
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns detected. The skill provides clear architectural guidance and routes to specialized implementation skills.
- [DATA_EXFILTRATION]: The skill explicitly includes a mandatory protocol (
sensitive-runtime-data-protection.md) to prevent the exfiltration of credentials. It forbids returning thex-cloudbase-contextheader, which contains temporary cloud credentials, and prevents echoing sensitive environment variables or request metadata in debug endpoints. - [COMMAND_EXECUTION]: The skill utilizes a suite of CloudBase management tools (e.g.,
manageEnv,manageGateway,manageFunctions). These are standard administrative tools for the platform. The skill mandates aconfirm="yes"parameter for all paid or destructive operations to ensure user oversight. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with external documentation through
searchKnowledgeBase. However, it mitigates injection risks by requiring the agent to follow thechange-safety-protocol.md, which demands explicit user confirmation before any code or configuration change is applied based on that data. - [EXTERNAL_DOWNLOADS]: The skill references official Tencent Cloud and CloudBase domains for documentation and console access, which are well-known services associated with the skill's author (
tencentcloudbase).
Audit Metadata