auth-nodejs-cloudbase

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and sibling skills hosted on cnb.cool, which is Tencent's official Cloud Native Build platform. These are legitimate vendor resources used for providing context and documentation.
  • [CREDENTIALS_UNSAFE]: The skill provides instructions on how to load a private key file (tcb_custom_login.json) for custom authentication. It includes explicit security warnings to keep this file secret, never bundle it into frontend code, and protect it as a private key. No hardcoded credentials or secrets are present in the examples.
  • [COMMAND_EXECUTION]: The skill does not contain any shell commands, subprocess calls, or instructions to execute arbitrary code. The examples are limited to standard Node.js SDK usage.
  • [PROMPT_INJECTION]: There are no patterns suggesting attempts to bypass AI safety guidelines, override system instructions, or extract sensitive prompt data. The instructions focus entirely on technical implementation of authentication flows.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 04:24 PM
Security Audit — agent-trust-hub — auth-nodejs-cloudbase