cloudbase-sites-runtime

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user prompts (e.g., requests to build specific app features) and project files to generate code and perform deployments. This combination of external data ingestion and significant capabilities creates a potential attack surface.
  • Ingestion points: User prompts for application features and project-specific files like package.json and app.json (SKILL.md).
  • Boundary markers: Mentions the use of "deterministic Chinese/English intent rules" for session activation to prevent unintended triggers.
  • Capability inventory: Includes bash, Edit, and Write tools, alongside a custom cloudbase-sites CLI for process management and manageApps for cloud deployment.
  • Sanitization: No explicit mention of input sanitization or output escaping when interpolating user-requested features into source code.
  • [COMMAND_EXECUTION]: Orchestrates the development lifecycle by executing a vendor-provided CLI tool (cloudbase-sites) with various subcommands such as init, preview, save, deploy, and rollback. It also resolution logic to find the binary within specific plugin root directories.
  • [EXTERNAL_DOWNLOADS]: Downloads official React and Vue project templates from the vendor's distribution domain (static.cloudbase.net) when initializing new projects.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — cloudbase-sites-runtime