cloudbase-guidelines
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the
@cloudbase/cloudbase-mcppackage vianpx. This is an official package associated with the skill's author, tencentcloudbase.- [COMMAND_EXECUTION]: Provides configuration and usage examples for executing commands vianpxand themcporterCLI to manage CloudBase services and tools.- [DATA_EXFILTRATION]: Guidelines include configuration templates with placeholders for credentials like Secret ID and Secret Key. No hardcoded secrets were found within the skill.- [PROMPT_INJECTION]: The instructions direct the agent to read external project files likeREADME.mdto determine deployment status. This ingestion point for untrusted data is a known surface for indirect prompt injection but is presented here as part of standard developer workflows.
Audit Metadata