ai-model-nodejs
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves ingesting and processing untrusted user data via the
messagesarray ingenerateTextandstreamTextmethods, as well as thepromptfield ingenerateImage. This data is passed directly to external AI models, creating a potential surface for indirect prompt injection attacks.\n - Ingestion points: Untrusted data enters the agent context through the
messagesparameter inapi-reference.mdand thepromptparameter inapi-reference.md.\n - Boundary markers: The skill does not define specific boundary markers or instructions for the AI to ignore malicious prompts embedded within user data.\n
- Capability inventory: The skill allows for network operations to external AI services through the
@cloudbase/node-sdkand includes potential file system access if implemented by the agent logic.\n - Sanitization: There is no evidence of explicit sanitization, escaping, or schema validation for the external content before it is interpolated into model requests.\n- [COMMAND_EXECUTION]: The skill instructs the user to execute
npm install @cloudbase/node-sdkinSKILL.mdto set up the environment. This is a standard and expected task for Node.js development.\n- [EXTERNAL_DOWNLOADS]: The skill provides links to official Tencent Cloud domains (buy.cloud.tencent.comandtcb.cloud.tencent.com) for managing environment resources and AI model configurations. These are recognized as legitimate vendor resources.
Audit Metadata