cloudbase-agent

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of AI agents that process user-supplied messages and tool outputs, creating a standard surface for indirect prompt injection.
  • Ingestion points: The RunAgentInput and ClientState structures in ts/agui-protocol.md and ts/adapter-langgraph.md define how external data, including messages and tools, enter the agent's context.
  • Capability inventory: The skill enables agents to perform network operations via SSE streaming and execute tools both on the server and the client side (ts/agui-protocol.md).
  • Boundary markers: The documentation does not explicitly detail the use of delimiters for untrusted input; however, it leverages established frameworks like LangGraph and LangChain which have their own integration patterns.
  • Sanitization: Not explicitly addressed in the snippets, implying reliance on the developer's implementation or the underlying framework's safety features.
  • [EXTERNAL_DOWNLOADS]: The skill references several official packages from the @cloudbase and @ag-ui scopes (e.g., @cloudbase/agent-server, @cloudbase/agent-adapter-langgraph, @ag-ui/client). These are vendor-provided resources from the author 'tencentcloudbase' and are considered safe.
  • [COMMAND_EXECUTION]: The documentation includes standard deployment commands such as setting executable permissions (chmod +x scf_bootstrap) and using the manageAgent MCP tool for cloud deployment. These operations are restricted to the intended deployment workflow and show no signs of malicious intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 09:21 AM
Security Audit — agent-trust-hub — cloudbase-agent