cloud-api-operations
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to reference documentation and SDK source code from verified vendor domains and repositories, such as
cloud.tencent.com,docs.cloudbase.net, andgithub.com/TencentCloud. These downloads are used neutrally to discover and verify API schemas and parameter requirements.\n- [COMMAND_EXECUTION]: The skill utilizes thecallCloudApitool to execute control-plane operations on various Tencent Cloud services. It provides specific sequences of commands, called 'recipes', to perform tasks like configuring alerts for database instances, ensuring that all execution follows proven, documented workflows.\n- [PRIVILEGE_ESCALATION]: The skill manages agent permissions by providing users with one-click authorization links to the official Tencent Cloud console. This allows users to manually grant specific pre-defined Access Management (CAM) policies (e.g.,QcloudMonitorFullAccess) to the agent's service role, maintaining explicit user control over permission changes.\n- [INDIRECT_PROMPT_INJECTION]: The skill implements a strategy to mitigate risks associated with processing user-provided API parameters. It requires the agent to verify all action names and parameter shapes against official documentation or SDK source code before execution. The evidence chain is as follows: \n * Ingestion points: User input provided for API parameters inSKILL.mdandreferences/recipes/pg-storage-alarm.md.\n * Boundary markers: The structured nature of thecallCloudApiparameters. \n * Capability inventory: The use ofcallCloudApifor cloud resource management as documented inreferences/calling-methods.md.\n * Sanitization: The mandatory requirement to cross-reference input against official vendor SDK models to prevent the agent from being misled by injected instructions in user-controlled data.
Audit Metadata