auth-nodejs-cloudbase

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill uses require() with a path constructed via path.join() to load credential JSON files. While standard for Node.js configuration, this represents a dynamic loading pattern.
  • [EXTERNAL_DOWNLOADS]: The skill references the @cloudbase/node-sdk package for installation via npm. This is the official SDK provided by the vendor and is a trusted resource.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for processing external user data such as phone numbers, emails, and custom identifiers. -- Ingestion points: Found in the queryUserInfo and createTicket scenarios where user-provided values are passed to SDK methods. -- Boundary markers: The skill instructs the agent to follow exact SDK parameter shapes and official documentation. -- Capability inventory: The skill's code initializes the SDK, loads credential files from the filesystem, and performs user authentication tasks. -- Sanitization: The documentation specifies character and length constraints for customUserId to mitigate injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 09:21 AM
Security Audit — agent-trust-hub — auth-nodejs-cloudbase