cloud-functions
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a legitimate development resource for Tencent CloudBase functions. All described functionalities, including network operations, code deployment, and credential management, are aligned with the intended purpose and utilize official vendor infrastructure.
- [PROMPT_INJECTION]: The static detector hits for concealment were evaluated as false positives. Instructions like "Never ask the user to paste the password into chat" and "Do not print it, commit it, return it to a client" are intended to protect the user's security and prevent the accidental inclusion of secrets in chat history, rather than being an attempt to hide malicious actions from the user.
- [CREDENTIALS_UNSAFE]: The skill includes extensive guidelines for secure secret management. It directs users to use environment variables and server-side API keys instead of hardcoding credentials, and it explicitly warns against returning sensitive headers or environment variables in function responses, referencing a specific "Sensitive Runtime Data Protection" protocol.
- [EXTERNAL_DOWNLOADS]: All external resource references are directed toward official Tencent Cloud domains. References include
tcr.tencentcloudapi.comfor registry management andccr.ccs.tencentyun.comfor container image deployment, which are necessary for the skill's stated purpose.
Audit Metadata