ai-model-nodejs

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves ingesting and processing untrusted user data via the messages array in generateText and streamText methods, as well as the prompt field in generateImage. This data is passed directly to external AI models, creating a potential surface for indirect prompt injection attacks.\n
  • Ingestion points: Untrusted data enters the agent context through the messages parameter in api-reference.md and the prompt parameter in api-reference.md.\n
  • Boundary markers: The skill does not define specific boundary markers or instructions for the AI to ignore malicious prompts embedded within user data.\n
  • Capability inventory: The skill allows for network operations to external AI services through the @cloudbase/node-sdk and includes potential file system access if implemented by the agent logic.\n
  • Sanitization: There is no evidence of explicit sanitization, escaping, or schema validation for the external content before it is interpolated into model requests.\n- [COMMAND_EXECUTION]: The skill instructs the user to execute npm install @cloudbase/node-sdk in SKILL.md to set up the environment. This is a standard and expected task for Node.js development.\n- [EXTERNAL_DOWNLOADS]: The skill provides links to official Tencent Cloud domains (buy.cloud.tencent.com and tcb.cloud.tencent.com) for managing environment resources and AI model configurations. These are recognized as legitimate vendor resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 02:51 AM
Security Audit — agent-trust-hub — ai-model-nodejs