auth-tool-cloudbase
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill facilitates the configuration of CloudBase authentication providers through structured MCP tools. It defines clear boundaries between management tools and application-side configuration to prevent privilege confusion.
- [SAFE]: Documentation provides explicit security guidance for sensitive features, such as warning that anonymous login is disabled by default and requires additional implementation like AuthGuard to be secure.
- [SAFE]: External integrations with WeChat and Google follow official documentation patterns and point to verified domains. Examples use placeholders for all secrets and credentials.
- [SAFE]: The skill instructions proactively prevent potential injection by directing the agent to use local relative paths for sibling skills and forbidding the fetching of remote skill content into the context.
Audit Metadata