minimal-web-baas-demo
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill guides the agent to perform standard development tasks including package installation via
npmorpnpmand database management using thetcbCLI. These operations are consistent with the skill's primary purpose of setting up a CloudBase environment. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates an architectural pattern where the agent reads data from external sources, specifically CloudBase NoSQL and Relational databases (
app.database(),app.rdb()), and displays it in a web interface. - Ingestion points: Data is fetched from database collections and tables during the 'Browser CRUD' step (SKILL.md).
- Boundary markers: The skill includes a protective instruction prohibiting the HTTP-fetching of remote skill or protocol markdown into the agent context (SKILL.md).
- Capability inventory: The agent has the ability to install Node.js packages, execute CLI commands, and modify local template files.
- Sanitization: No specific sanitization logic is prescribed for the data retrieved from the database, representing a standard surface for indirect prompt injection if the processed data contains instructions.
Audit Metadata