cloudbase-guidelines

Pass

Audited by Gen Agent Trust Hub on Mar 10, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the @cloudbase/cloudbase-mcp package via npx. This is an official package associated with the skill's author, tencentcloudbase.- [COMMAND_EXECUTION]: Provides configuration and usage examples for executing commands via npx and the mcporter CLI to manage CloudBase services and tools.- [DATA_EXFILTRATION]: Guidelines include configuration templates with placeholders for credentials like Secret ID and Secret Key. No hardcoded secrets were found within the skill.- [PROMPT_INJECTION]: The instructions direct the agent to read external project files like README.md to determine deployment status. This ingestion point for untrusted data is a known surface for indirect prompt injection but is presented here as part of standard developer workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 10, 2026, 03:41 AM