cloudbase-agent
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The deployment guide (
py/agent-deployment.md) provides shell scripts for building the agent environment. These scripts perform operations such as directory deletion (rm -rf), package installation (pip install), and permission modification (chmod). These actions are documented as necessary steps for packaging Python dependencies for deployment to CloudBase. - [INDIRECT_PROMPT_INJECTION]: The skill framework processes untrusted user input and provides significant capabilities, including tool execution and cloud deployment. To mitigate risks, the documentation includes "Human-in-the-Loop" patterns (e.g., in
py/references/recipes.md) that require explicit approval for sensitive actions like sending emails. - [DYNAMIC_EXECUTION]: The deployment workflow includes Python scripts that are generated or executed at runtime to verify environment integrity. Specifically,
py/agent-deployment.mdincludes scripts that use static analysis (astmodule) and dynamic imports to ensure all required dependencies are correctly packaged in the local environment. - [EXTERNAL_DOWNLOADS]: The skill integrates with external services such as Coze (
api.coze.com) and utilizes various vendor-owned packages from PyPI and NPM. These resources are consistent with the skill's purpose as a cloud-based agent SDK.
Audit Metadata