cloudbase-agent
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of AI agents that process user-supplied messages and tool outputs, creating a standard surface for indirect prompt injection.
- Ingestion points: The
RunAgentInputandClientStatestructures ints/agui-protocol.mdandts/adapter-langgraph.mddefine how external data, includingmessagesandtools, enter the agent's context. - Capability inventory: The skill enables agents to perform network operations via SSE streaming and execute tools both on the server and the client side (
ts/agui-protocol.md). - Boundary markers: The documentation does not explicitly detail the use of delimiters for untrusted input; however, it leverages established frameworks like LangGraph and LangChain which have their own integration patterns.
- Sanitization: Not explicitly addressed in the snippets, implying reliance on the developer's implementation or the underlying framework's safety features.
- [EXTERNAL_DOWNLOADS]: The skill references several official packages from the
@cloudbaseand@ag-uiscopes (e.g.,@cloudbase/agent-server,@cloudbase/agent-adapter-langgraph,@ag-ui/client). These are vendor-provided resources from the author 'tencentcloudbase' and are considered safe. - [COMMAND_EXECUTION]: The documentation includes standard deployment commands such as setting executable permissions (
chmod +x scf_bootstrap) and using themanageAgentMCP tool for cloud deployment. These operations are restricted to the intended deployment workflow and show no signs of malicious intent.
Audit Metadata