web-development

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes official Tencent CloudBase resources, including the JS SDK fetched from the vendor CDN (https://static.cloudbase.net/cloudbase-js-sdk/latest/cloudbase.full.js). It also recommends standard installation of @cloudbase/js-sdk and @cloudbase/node-sdk via official package registries.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute standard development and build commands such as 'npm run dev', 'npm run build', and 'tsc --noEmit' for verification. It also leverages platform management tools (manageHosting, manageCloudRun, manageFunctions) for deployment operations.
  • [INDIRECT_PROMPT_INJECTION]: The requirement to use the 'agent-browser' tool for verifying web applications introduces an attack surface where malicious content on a page could attempt to influence the agent. | Ingestion points: The agent reads content from rendered web pages to verify routing, auth, and UI flows (browser-testing.md). | Boundary markers: The instructions lack explicit delimiters for browser output, though they define specific reporting requirements for verification results. | Capability inventory: The skill possesses the ability to modify the filesystem, install packages, and perform deployment actions. | Sanitization: No specific filtering or sanitization of content ingested via the browser is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 03:39 PM
Security Audit — agent-trust-hub — web-development