cloudbase-platform

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns detected. The skill provides clear architectural guidance and routes to specialized implementation skills.
  • [DATA_EXFILTRATION]: The skill explicitly includes a mandatory protocol (sensitive-runtime-data-protection.md) to prevent the exfiltration of credentials. It forbids returning the x-cloudbase-context header, which contains temporary cloud credentials, and prevents echoing sensitive environment variables or request metadata in debug endpoints.
  • [COMMAND_EXECUTION]: The skill utilizes a suite of CloudBase management tools (e.g., manageEnv, manageGateway, manageFunctions). These are standard administrative tools for the platform. The skill mandates a confirm="yes" parameter for all paid or destructive operations to ensure user oversight.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external documentation through searchKnowledgeBase. However, it mitigates injection risks by requiring the agent to follow the change-safety-protocol.md, which demands explicit user confirmation before any code or configuration change is applied based on that data.
  • [EXTERNAL_DOWNLOADS]: The skill references official Tencent Cloud and CloudBase domains for documentation and console access, which are well-known services associated with the skill's author (tencentcloudbase).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — cloudbase-platform