cloudbase-agent

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The deployment guide (py/agent-deployment.md) provides shell scripts for building the agent environment. These scripts perform operations such as directory deletion (rm -rf), package installation (pip install), and permission modification (chmod). These actions are documented as necessary steps for packaging Python dependencies for deployment to CloudBase.
  • [INDIRECT_PROMPT_INJECTION]: The skill framework processes untrusted user input and provides significant capabilities, including tool execution and cloud deployment. To mitigate risks, the documentation includes "Human-in-the-Loop" patterns (e.g., in py/references/recipes.md) that require explicit approval for sensitive actions like sending emails.
  • [DYNAMIC_EXECUTION]: The deployment workflow includes Python scripts that are generated or executed at runtime to verify environment integrity. Specifically, py/agent-deployment.md includes scripts that use static analysis (ast module) and dynamic imports to ensure all required dependencies are correctly packaged in the local environment.
  • [EXTERNAL_DOWNLOADS]: The skill integrates with external services such as Coze (api.coze.com) and utilizes various vendor-owned packages from PyPI and NPM. These resources are consistent with the skill's purpose as a cloud-based agent SDK.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:27 PM
Security Audit — agent-trust-hub — cloudbase-agent