cloudbase

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the tcb CLI and npx (e.g., npx @cloudbase/cloudbase-mcp, npx mcporter) to perform environment management and resource deployment. It also uses node -e one-liners for cross-platform JSON configuration updates during site onboarding. These are standard operational procedures for developer tooling.
  • [EXTERNAL_DOWNLOADS]: The skill guides the user to install official vendor packages from the NPM registry (such as @cloudbase/cli, @cloudbase/cloudbase-mcp, and the cloudbase-plugin). It also communicates with official Tencent CloudBase API endpoints (e.g., tcb-api.cloud.tencent.com and tcb-api.tencentcloud.com) for management tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted local data, such as .cloudbase/project.json and README.md files, to determine deployment state and project configuration. This surface is managed through instructions that require explicit environment resolution and advise against the use of hardcoded secrets or sensitive credentials within project files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:27 PM
Security Audit — agent-trust-hub — cloudbase