cloudbase

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data, creating an attack surface for indirect prompt injection.
  • Ingestion points: The skill reads user-provided project files (Web, Mini Programs, Cloud Functions), requirement documents, and task lists (tasks.md) to guide development and deployment.
  • Capability inventory: The skill has high-privilege capabilities including the ability to write project configuration files, execute shell commands via the tcb CLI, and call management APIs to create or update cloud functions, databases, and hosting environments.
  • Boundary markers: The instructions do not specify the use of security delimiters or explicit "ignore embedded instructions" warnings when processing user-supplied code or requirements.
  • Sanitization: There are no explicit requirements for sanitizing or validating the logic of user-provided code before it is deployed to the cloud environment.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation and use of external tools and plugins.
  • Evidence: Instructions include npx plugins add TencentCloudBase/cloudbase-plugin for MCP setup and npm i -g @cloudbase/cli for CLI fallback.
  • Context: These resources are official packages belonging to the skill's author (tencentcloudbase) and are standard for the advertised functionality of the cloud platform.
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands to manage cloud infrastructure.
  • Evidence: The tooling-fallback.md and deployment-workflow.md files contain instructions for running tcb login, tcb env use, and domain-specific deployment commands like tcb fn deploy and tcb hosting deploy.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — cloudbase