auth-web-cloudbase
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the official vendor package
@cloudbase/js-sdk. It also references documentation and management consoles on the vendor's official domains (tencentcloudbase.comandcloudbase.net). - [CREDENTIALS_UNSAFE]: The skill correctly identifies the difference between a publishable key (
accessKey) and secrets. It explicitly instructs developers to store the publishable key in.env.localfiles rather than hardcoding them in source files, which aligns with industry security best practices. - [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted user input (usernames, emails, passwords) for authentication flows.
- Ingestion points: Registration and login form handlers described in
SKILL.mdandreferences/extended-guide.md. - Boundary markers: The instructions rely on standard SDK parameter encapsulation to delimit data.
- Capability inventory: The skill performs network-based authentication requests via the CloudBase SDK but does not execute arbitrary system commands or write to arbitrary files.
- Sanitization: Input sanitization is deferred to the
@cloudbase/js-sdklibrary and the CloudBase backend services.
Audit Metadata