Scan Report
5 /100
cloudbase
CloudBase is a full-stack development and deployment toolkit for building and launching websites, Web apps, WeChat Mini Programs, and mobile apps with backend, database, hosting, cloud functions, AI capabilities, Agent, and UI guidance.
CloudBase skill is a legitimate documentation package for Tencent CloudBase platform with no malicious behavior found. All code snippets are documentation examples, all URLs point to official/legitimate services, and no security violations detected.
Safe to install
This skill is safe to use. No additional security controls needed.
Findings 2 items
| Severity | Finding | Location |
|---|---|---|
| Info | HTML Comment Markers in Deployment Docs Doc Mismatch | references/cloudbase-agent/py/agent-deployment.md:26 |
| Info | Environment Variable References in Documentation Sensitive Access | references/cloudbase-agent/py/skill.md:109 |
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Filesystem | NONE | NONE | — | Documentation-only; no filesystem operations in skill |
| Network | NONE | NONE | — | Skill documents API usage; no network operations performed by skill itself |
| Shell | NONE | NONE | — | subprocess mentioned only in deployment documentation examples |
| Environment | NONE | NONE | — | os.environ.get() documented for configuration purposes only |
| Skill Invoke | NONE | NONE | — | Skill references other CloudBase skills for routing |
| Clipboard | NONE | NONE | — | No clipboard operations found |
| Browser | NONE | NONE | — | No browser automation found |
| Database | NONE | NONE | — | Skill documents CloudBase DB usage; no direct database operations |
31 findings
Medium External URL 外部 URL
https://static.cloudbase.net/cloudbase-js-sdk/latest/cloudbase.full.js SKILL.md:67 Medium External URL 外部 URL
https://cloud.tencent.com/document/product/876/75213 SKILL.md:158 Medium External URL 外部 URL
https://tcb.cloud.tencent.com/dev?envId=$ SKILL.md:242 Medium External URL 外部 URL
https://open.weixin.qq.com/cgi-bin/readtemplate?t=regist/regist_tmpl references/auth-tool/SKILL.md:273 Medium External URL 外部 URL
https://console.cloud.google.com/apis/credentials references/auth-tool/SKILL.md:309 Medium External URL 外部 URL
https://accounts.google.com/o/oauth2/v2/auth references/auth-tool/SKILL.md:328 Medium External URL 外部 URL
https://qcloudimg.tencent-cloud.cn/raw/f9131c00dcbcbccd5899a449d68da3ba.png references/auth-tool/SKILL.md:337 Medium External URL 外部 URL
https://tcb.cloud.tencent.com/dev?envId= references/auth-tool/SKILL.md:395 Medium External URL 外部 URL
https://your-app.com references/cloud-storage-web/SKILL.md:154 Medium External URL 外部 URL
https://api.coze.com references/cloudbase-agent/py/adapter-coze.md:49 Medium External URL 外部 URL
https://[email protected]/xxx references/cloudbase-agent/py/references/observability.md:233 Medium External URL 外部 URL
http://apm-server:8200 references/cloudbase-agent/py/references/observability.md:301 Medium External URL 外部 URL
http://grafana:3000/api/dashboards/import references/cloudbase-agent/py/references/observability.md:328 Medium External URL 外部 URL
https://api.example.com/data references/cloudbase-agent/py/references/tools.md:55 Medium External URL 外部 URL
https://api.example.com/search?q= references/cloudbase-agent/py/references/tools.md:87 Medium External URL 外部 URL
https://your-frontend.com references/cloudbase-agent/py/server-quickstart.md:430 Medium External URL 外部 URL
https://docs.ag-ui.com/concepts/events references/cloudbase-agent/ts/adapter-development.md:51 Medium External URL 外部 URL
https://cloud.langfuse.com/api/public/otlp/v1/traces references/cloudbase-agent/ts/server-quickstart.md:128 Medium External URL 外部 URL
https://docs.ag-ui.com references/cloudbase-agent/ts/ui-clients.md:27 Medium External URL 外部 URL
https://console.cloud.tencent.com/tcb/hosting references/cloudbase-platform/SKILL.md:251 Medium External URL 外部 URL
https://tcb.cloud.tencent.com/dev?#/identity/token-management references/http-api/SKILL.md:145 Medium External URL 外部 URL
https://cloud1-abc.api.tcloudbasegateway.com references/http-api/SKILL.md:174 Medium External URL 外部 URL
https://cloud1-abc.api.intl.tcloudbasegateway.com references/http-api/SKILL.md:188 Medium External URL 外部 URL
https://your-env-id.api.tcloudbasegateway.com/v1/functions/YOUR_FUNCTION_NAME references/http-api/SKILL.md:214 Medium External URL 外部 URL
https://your-env.api.tcloudbasegateway.com/v1/rdb/rest/course?select=name references/http-api/SKILL.md:265 Medium External URL 外部 URL
https://your-env.api.tcloudbasegateway.com/v1/rdb/rest/course references/http-api/SKILL.md:287 Medium External URL 外部 URL
https://your-env.api.tcloudbasegateway.com/v1/rdb/rest/course?id=eq.1 references/http-api/SKILL.md:306 Medium External URL 外部 URL
https://tcb.cloud.tencent.com/dev references/no-sql-web-sdk/security-rules.md:45 Medium External URL 外部 URL
https://tcb.cloud.tencent.com/dev#/db/doc/model references/no-sql-web-sdk/security-rules.md:69 Medium External URL 外部 URL
https://cloud.tencent.com/document/product/876/123478 references/no-sql-web-sdk/security-rules.md:890 Info Email 邮箱地址
[email protected] references/cloudbase-agent/py/references/observability.md:233 File Tree
68 files · 513.5 KB · 17057 lines Markdown 68f · 17057L
├─
▾
references
│ ├─
▾
ai-model-nodejs
│ │ └─
SKILL.md
Markdown
│ ├─
▾
ai-model-web
│ │ └─
SKILL.md
Markdown
│ ├─
▾
ai-model-wechat
│ │ └─
SKILL.md
Markdown
│ ├─
▾
auth-nodejs
│ │ └─
SKILL.md
Markdown
│ ├─
▾
auth-tool
│ │ ├─
checklist.md
Markdown
│ │ └─
SKILL.md
Markdown
│ ├─
▾
auth-web
│ │ └─
SKILL.md
Markdown
│ ├─
▾
auth-wechat
│ │ └─
SKILL.md
Markdown
│ ├─
▾
cloud-functions
│ │ ├─
▾
references
│ │ │ ├─
event-functions.md
Markdown
│ │ │ ├─
http-functions.md
Markdown
│ │ │ └─
operations-and-config.md
Markdown
│ │ ├─
checklist.md
Markdown
│ │ ├─
references.md
Markdown
│ │ └─
SKILL.md
Markdown
│ ├─
▾
cloud-storage-web
│ │ └─
SKILL.md
Markdown
│ ├─
▾
cloudbase-agent
│ │ ├─
▾
py
│ │ │ ├─
▾
references
│ │ │ │ ├─
observability.md
Markdown
│ │ │ │ ├─
recipes.md
Markdown
│ │ │ │ ├─
server.md
Markdown
│ │ │ │ ├─
storage.md
Markdown
│ │ │ │ └─
tools.md
Markdown
│ │ │ ├─
adapter-coze.md
Markdown
│ │ │ ├─
adapter-development.md
Markdown
│ │ │ ├─
adapter-langgraph.md
Markdown
│ │ │ ├─
agent-deployment.md
Markdown
│ │ │ ├─
authentication.md
Markdown
│ │ │ ├─
server-quickstart.md
Markdown
│ │ │ └─
skill.md
Markdown
│ │ ├─
▾
ts
│ │ │ ├─
adapter-development.md
Markdown
│ │ │ ├─
adapter-langchain.md
Markdown
│ │ │ ├─
adapter-langgraph.md
Markdown
│ │ │ ├─
agent-deployment.md
Markdown
│ │ │ ├─
agui-protocol.md
Markdown
│ │ │ ├─
server-quickstart.md
Markdown
│ │ │ ├─
skill.md
Markdown
│ │ │ ├─
ui-clients.md
Markdown
│ │ │ └─
ui-miniprogram.md
Markdown
│ │ └─
SKILL.md
Markdown
│ ├─
▾
cloudbase-platform
│ │ └─
SKILL.md
Markdown
│ ├─
▾
cloudrun-development
│ │ └─
SKILL.md
Markdown
│ ├─
▾
data-model-creation
│ │ └─
SKILL.md
Markdown
│ ├─
▾
http-api
│ │ ├─
checklist.md
Markdown
│ │ └─
SKILL.md
Markdown
│ ├─
▾
miniprogram-development
│ │ ├─
▾
references
│ │ │ └─
cloudbase-integration.md
Markdown
│ │ └─
SKILL.md
Markdown
│ ├─
▾
no-sql-web-sdk
│ │ ├─
aggregation.md
Markdown
│ │ ├─
complex-queries.md
Markdown
│ │ ├─
crud-operations.md
Markdown
│ │ ├─
geolocation.md
Markdown
│ │ ├─
pagination.md
Markdown
│ │ ├─
realtime.md
Markdown
│ │ ├─
security-rules.md
Markdown
│ │ └─
SKILL.md
Markdown
│ ├─
▾
no-sql-wx-mp-sdk
│ │ ├─
aggregation.md
Markdown
│ │ ├─
complex-queries.md
Markdown
│ │ ├─
crud-operations.md
Markdown
│ │ ├─
geolocation.md
Markdown
│ │ ├─
pagination.md
Markdown
│ │ ├─
security-rules.md
Markdown
│ │ └─
SKILL.md
Markdown
│ ├─
▾
relational-database-tool
│ │ └─
SKILL.md
Markdown
│ ├─
▾
relational-database-web
│ │ └─
SKILL.md
Markdown
│ ├─
▾
spec-workflow
│ │ └─
SKILL.md
Markdown
│ ├─
▾
ui-design
│ │ ├─
checklist.md
Markdown
│ │ └─
SKILL.md
Markdown
│ └─
▾
web-development
│ ├─
browser-testing.md
Markdown
│ ├─
frameworks.md
Markdown
│ └─
SKILL.md
Markdown
└─
SKILL.md
Markdown
Security Positives
✓ Documentation-only skill with no executable code files
✓ All code snippets are example patterns with placeholder values
✓ No credential harvesting, data exfiltration, or C2 communication
✓ All external URLs point to official Tencent CloudBase and legitimate third-party services (OpenAI, Coze, Sentry)
✓ No obfuscation, base64 execution, or anti-analysis techniques
✓ Standard JWT parsing (atob for base64 decode of JWT payload) is legitimate
✓ HTML comments are documented AI instruction markers, not hidden malicious code
✓ Pre-scan flagged no scripts, no .env files, no sensitive file access