cloudbase
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
tcbCLI andnpx(e.g.,npx @cloudbase/cloudbase-mcp,npx mcporter) to perform environment management and resource deployment. It also usesnode -eone-liners for cross-platform JSON configuration updates during site onboarding. These are standard operational procedures for developer tooling. - [EXTERNAL_DOWNLOADS]: The skill guides the user to install official vendor packages from the NPM registry (such as
@cloudbase/cli,@cloudbase/cloudbase-mcp, and thecloudbase-plugin). It also communicates with official Tencent CloudBase API endpoints (e.g.,tcb-api.cloud.tencent.comandtcb-api.tencentcloud.com) for management tasks. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted local data, such as
.cloudbase/project.jsonandREADME.mdfiles, to determine deployment state and project configuration. This surface is managed through instructions that require explicit environment resolution and advise against the use of hardcoded secrets or sensitive credentials within project files.
Audit Metadata