cloud-functions

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references official Tencent Cloud documentation (docs.cloudbase.net) and integrates with vendor-specific services including TCR (Tencent Container Registry) and COS (Cloud Object Storage) for function deployment.
  • [COMMAND_EXECUTION]: Instructions include standard deployment-related commands such as chmod +x for bootstrap scripts and docker for building container images. These operations are restricted to the local development and deployment environment and are essential for the primary function of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from HTTP request bodies, event triggers, and cloud execution logs. It mitigates injection risks by providing explicit sanitization protocols, specifically prohibiting the echoing of raw headers, environment variables, or platform-injected context objects back to users or clients.
  • [CREDENTIALS_SAFE]: Provides clear instructions for secure credential management, recommending the use of environment variables and platform-issued API keys over hardcoded secrets. It specifically warns against passing passwords or secrets as tool arguments or in chat logs, identifying these as common security mistakes.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 07:20 AM
Security Audit — agent-trust-hub — cloud-functions