auth-web-cloudbase

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the official vendor package @cloudbase/js-sdk. It also references documentation and management consoles on the vendor's official domains (tencentcloudbase.com and cloudbase.net).
  • [CREDENTIALS_UNSAFE]: The skill correctly identifies the difference between a publishable key (accessKey) and secrets. It explicitly instructs developers to store the publishable key in .env.local files rather than hardcoding them in source files, which aligns with industry security best practices.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted user input (usernames, emails, passwords) for authentication flows.
  • Ingestion points: Registration and login form handlers described in SKILL.md and references/extended-guide.md.
  • Boundary markers: The instructions rely on standard SDK parameter encapsulation to delimit data.
  • Capability inventory: The skill performs network-based authentication requests via the CloudBase SDK but does not execute arbitrary system commands or write to arbitrary files.
  • Sanitization: Input sanitization is deferred to the @cloudbase/js-sdk library and the CloudBase backend services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 09:21 AM
Security Audit — agent-trust-hub — auth-web-cloudbase