ai-model-nodejs

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted user input for text and image generation while possessing access to powerful cloud management tools that could be abused if the AI is manipulated.
  • Ingestion points: Untrusted data enters the agent context through the messages array in generateText/streamText and the prompt string in generateImage (found in references/api-reference.md).
  • Boundary markers: The instructions do not specify the use of delimiters or explicit warnings for the AI to ignore potentially malicious commands embedded in user-provided prompts.
  • Capability inventory: The skill utilizes the callCloudApi tool with the tcb service to manage environment settings and AI models. It also uses manageFunctions to configure cloud functions (found in SKILL.md).
  • Sanitization: There is no evidence of input validation, filtering, or sanitization described for the data passed to the AI models.
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to install dependencies and execute platform-specific tools to configure the cloud environment.
  • Evidence: The skill uses npm install for the SDK and makes calls to MCP tools including queryEnv, callCloudApi, and manageFunctions to interact with Tencent Cloud resources.
  • [EXTERNAL_DOWNLOADS]: The skill references the official vendor SDK from a standard registry.
  • Evidence: Downloads the @cloudbase/node-sdk package from the official NPM registry, which is a well-known service and targets the vendor's own infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 09:21 AM
Security Audit — agent-trust-hub — ai-model-nodejs