minimal-web-baas-demo

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill guides the agent to perform standard development tasks including package installation via npm or pnpm and database management using the tcb CLI. These operations are consistent with the skill's primary purpose of setting up a CloudBase environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates an architectural pattern where the agent reads data from external sources, specifically CloudBase NoSQL and Relational databases (app.database(), app.rdb()), and displays it in a web interface.
  • Ingestion points: Data is fetched from database collections and tables during the 'Browser CRUD' step (SKILL.md).
  • Boundary markers: The skill includes a protective instruction prohibiting the HTTP-fetching of remote skill or protocol markdown into the agent context (SKILL.md).
  • Capability inventory: The agent has the ability to install Node.js packages, execute CLI commands, and modify local template files.
  • Sanitization: No specific sanitization logic is prescribed for the data retrieved from the database, representing a standard surface for indirect prompt injection if the processed data contains instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:35 AM
Security Audit — agent-trust-hub — minimal-web-baas-demo