cloudbase-sites-runtime

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests potentially untrusted data from local files (e.g., package.json, app.json) and external instructions fetched via the searchKnowledgeBase tool. These inputs guide agent behavior without explicit boundary markers or sanitization. Ingestion points: Local configuration files and external knowledge base content. Boundary markers: Absent. Capability inventory: CLI execution, file system modification, git operations, and cloud deployments. Sanitization: Not specified.\n- [EXTERNAL_DOWNLOADS]: The skill downloads project templates from vendor-managed infrastructure (static.cloudbase.net) and retrieves domain-specific configuration from a remote knowledge base.\n- [COMMAND_EXECUTION]: Executes a vendor-provided command-line utility, cloudbase-sites, to manage the development server lifecycle, project initialization, and version control. It also uses git for session management and versioning.\n- [REMOTE_CODE_EXECUTION]: The skill facilitates the execution of remote templates and instructions, and is instructed to follow nextActions provided in the dynamic JSON output of the CLI tools.\n- [DATA_EXFILTRATION]: The manageApps tool is used to build and deploy local project files to public subdomains, which is the intended functionality but involves transferring local code to a remote environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 04:16 PM
Security Audit — agent-trust-hub — cloudbase-sites-runtime