cloudbase-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a defensive tool designed to improve project security by providing deterministic and semantic checks for CloudBase environments. All identified external resources, such as
@cloudbase/js-sdk, are official vendor libraries related to the author 'tencentcloudbase'. - [COMMAND_EXECUTION]: The skill provides a Node.js script in
references/lint-rules/README.mdintended for local code linting. The instructions require the agent or user to manually copy the code to a file (cloudbase-lint.mjs) and execute it. The script's logic is transparent and restricted to reading local source files and performing regex-based analysis without network or destructive operations. - [INDIRECT_PROMPT_INJECTION]: As a code review tool, the skill ingests untrusted data from the user's project directory. This is an inherent part of its functionality. The risk is minimized as the skill follows specific, structured rules (metadata, lint rules, and LLM checks) rather than executing arbitrary instructions found within the code being analyzed.
- [CREDENTIALS_UNSAFE]: Rule
AUTH-WEB-010andSEC001explicitly warn users against hardcoding secrets or echoing credentials in responses. This is a positive security feature aimed at preventing credential exposure.
Audit Metadata