cloudbase

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: Static analysis flagged potential concealment patterns in references/cloud-functions/SKILL.md and references/cloud-functions/references/http-function-credentials.md. These were manually verified as false positives. The text actually contains mandatory security instructions for the agent to prevent the leakage of sensitive runtime data (like x-cloudbase-context) and credentials to end users, which is a security best practice rather than malicious concealment.
  • [DYNAMIC_EXECUTION]: The skill provides a code review script (cloudbase-lint.mjs) in a markdown block in references/cloudbase-code-review/references/lint-rules/README.md. This script is intended for local project analysis and is presented transparently for the user to review and run manually. It uses standard Node.js modules (node:fs, node:path) to perform regex-based security and best-practice checks.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing official vendor packages such as @cloudbase/js-sdk and @cloudbase/node-sdk via npm. It also suggests the installation of the vendor's own toolkit using npx plugins add TencentCloudBase/cloudbase-plugin. All referenced domains (tencentcloudapi.com, tencentyun.com, tcloudbase.com) and package namespaces belong to the verified author tencentcloudbase.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets were found. The skill contains multiple guides (references/cloud-functions/references/http-function-credentials.md, references/auth-web-cloudbase/SKILL.md) that explicitly forbid hardcoding credentials and instead instruct the agent on how to securely inject them via environment variables or secret management tools provided by the platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 02:22 PM
Security Audit — agent-trust-hub — cloudbase