NYC

cloud-storage-web

Fail

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE] (SAFE): The skill provides documentation and code snippets for integrating CloudBase cloud storage into web applications. The behavior is consistent with the stated purpose.
  • [EXTERNAL_DOWNLOADS] (SAFE): The skill references the official '@cloudbase/js-sdk' package. No untrusted external scripts or binaries are downloaded or executed.
  • [CREDENTIALS_UNSAFE] (SAFE): No hardcoded API keys or credentials were found; initialization examples use placeholders for environment IDs.
  • [DATA_EXFILTRATION] (SAFE): The network operations described are standard SDK functions for storage management and do not involve unauthorized data access.
  • [SAFE] (SAFE): The automated security alert regarding 'file.co' is a false positive; the string is a fragment of the code property file.code and not an actual URL found in the skill content.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 17, 2026, 04:51 PM