Atlas / MCP servers / tencentcloudbase / CloudBase AI ToolKit

CloudBase AI ToolKitBLOCK

mcp/tencentcloudbase/cloudbase-ai-toolkit

Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP.

Verdict
BLOCK
Grade
F
Trust score
23 /100
Exposed tools
28 27r · 1w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
1,125
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

AI writes the code. CloudBase runs the backend.

The CloudBase integration layer for AI coding tools: Plugin installs the stack, Skills steer how code is written, MCP operates databases, functions, storage, and deploys from chat.

English · 简体中文 · [Docs][docs] · [Changelog][changelog] · [Issues][github-issues-link]

[![][npm-version-shield]][npm-link] [![][npm-downloads-shield]][npm-link] [![][github-stars-shield]][github-stars-link] [![][github-forks-shield]][github-forks-link] [![][github-issues-shield]][github-issues-link] ![][github-license-shield] ![][github-contributors-shield] [![][cnb-shield]][cnb-link] [![][deepwiki-shield]][deepwiki-link]

Recent updates

v2.34.x (2026-09)

  • i18n / IDE: full tool-copy localization with an instance-level lang, plus auth site / region params so international-site login and region routing resolve correctly
  • Cloud API: callCloudApi service allowlist widened to 57 with built-in version mapping (multi-version services such as tke / mongodb / vod require an explicit version)
  • Deploy / Env: new appBuild tool with hosting build neutralization; queryEnv reports the region actually applied and domains honors a passed envId
  • Skills / Docs: skill fallback reads now point at the official distribution repo with a references address list; SDK-first database decision gate for cloudrun; site doc links moved to the current Markdown addresses; post-deployment share offered after delivery in the expert packs and the deploy skills (opt-in, redacted, at most once)
  • Deploy / Apps: the cloud upload channel now completes end to end (deployApp accepts the timestamp getUploadUrl returns, getBuildLog accepts the build ID a deploy returns), and gateway route creation verifies t
Read from source at commit aec5fe0ad2ddOBSERVED · 2026-09-26
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add cloudbase-mcp -- npx -y @cloudbase/[email protected]
03

Exposed tools (28)

27 read · 1 write · 0 destructive.

ToolRiskDescription
ai_modelreadAI 大模型接入 API - 统一 AI 模型 HTTP API
authreadAuthentication API - 身份认证 HTTP API
auth-tool-cloudbasereadAuth tool skill
branded-skill-namereadSynthetic mismatch for name resolution
categoryProberead
cloudbasereadMain entry skill
cloudrunreadCloudRun API - 云托管服务 HTTP API
demoread
demo-agent-top-levelreadtest agent
downloadTemplateread
functionsreadCloud Functions API - 云函数 HTTP API
manageCloudRunread
manageHostingread
manageStorageread
miniprogram-developmentreadWeChat Mini Program skill
mysqldbreadMySQL RESTful API - 云开发 MySQL 数据库 HTTP API
nosqlreadNoSQL RESTful API - 文档型数据库 HTTP API
pgdbwritePostgreSQL RESTful API (PostgREST) - 云开发 PostgreSQL 数据库 HTTP API,含 exec-pgsql 直连 SQL
queryCloudRunread
queryHostingread
queryStorageread
storagereadStorage API - 云存储 HTTP API
tread
web-developmentreadWeb dev
分析函数错误read使用 AI 分析云函数错误并修复
创建云函数read使用 AI 创建云函数并生成调用代码
创建数据库表read使用 AI 设计并创建 MySQL 数据库表结构
集成登录功能read使用 AI 集成身份认证功能到项目中
04

Trust audit

BLOCKgrade F · trust 23/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (10 observation(s))
Shell
declared (11 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
config/.claude/skills/ai-model-nodejs/SKILL.md:257
1. **Run the two-step preflight before writing business code** — 1 eligibility: `queryEnv` → `callCloudApi(tcb, DescribeEnvPostpayPackage)` to confirm the Token Credits resource pack (text + image sha
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/build-allinone-skill.ts:140
const data = yaml.load(yamlContent) as { scenarios?: Record<string, any>[] };
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/build-skill-manifest.mjs:34
frontmatter: yaml.load(match[1]) || {},
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/check-prompts-sync.mjs:154
const config = yaml.load(fs.readFileSync(CONFIG_FILE, 'utf8'));
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/generate-prompts-data.mjs:27
const config = yaml.load(configContent);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/generate-prompts.mjs:35
frontmatter = yaml.load(frontmatterText) || {};
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/sync-cloudbase-plugin-skills.mjs:93
exec(`git clone --depth 1 --branch ${ref} ${repo} ${tmpDir}`, {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
mcp/src/interactive-server.ts:44
"metadata.google.internal",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
config/.claude/skills/ai-model-web/SKILL.md:226
> - **Enabling / configuring login providers** (phone SMS, email, WeChat Open Platform, username+password, OAuth, ...) → follow the **`auth-tool-cloudbase`** skill (backend config via `callCloudApi`).
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
config/.claude/skills/cloud-api-operations/SKILL.md:48
- Read the current credential scope from `auth` tools: `credential_scope: account` = account-level, reaches control-plane APIs subject to that identity's CAM policies; `env` = API Key, scoped to one e
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
config/.claude/skills/postgresql-development-cloudbase/SKILL.md:80
3. **Understand PG roles before writing code:** Publishable Key maps to `anon`; a logged-in user's access token maps to `authenticated`; API Key maps to `service_role` and bypasses RLS. Never expose A
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
config/.claude/skills/cloud-functions/SKILL.md:103
When `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action="getFunctionDeployStatus"` and that `taskId`; continue while the status 
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
config/source/skills/cloud-functions/SKILL.md:103
When `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action="getFunctionDeployStatus"` and that `taskId`; continue while the status 
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
connectors/cloudbase-intl/skills/references/cloud-functions/SKILL.md:103
When `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action="getFunctionDeployStatus"` and that `taskId`; continue while the status 
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
doc/prompts/cloud-functions.mdx:141
When `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action="getFunctionDeployStatus"` and that `taskId`; continue while the status 
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
plugin/cloudbase/skills/cloud-functions/SKILL.md:103
When `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action="getFunctionDeployStatus"` and that `taskId`; continue while the status 
Why it matters. asks the agent to act without the user's knowledge
MEDIUMInventory / provenance · inv.binary · CWE-1104
.codebuddy/.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
.codebuddy/worktrees/.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/api-contract-review
.agents/skills/api-contract-review
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/cloud-api-recipe-authoring
.agents/skills/cloud-api-recipe-authoring
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/codebuddy-ide-mcp-upgrade
.agents/skills/codebuddy-ide-mcp-upgrade
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/doc-freshness-review
.agents/skills/doc-freshness-review
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/docs-workflows
.agents/skills/docs-workflows
Why it matters. link not followed
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
mcp/src/utils/telemetry.ts:214
await this.postFetch('https://otheve.beacon.qq.com/analytics/v2_upload', payload);
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
plugin/cloudbase/hooks/plugin-telemetry.mjs:33
var BEACON_UPLOAD_URL = "https://otheve.beacon.qq.com/analytics/v2_upload";

Gates applied: critical_finding, instruction_override, no_behavioural_pass, undeclared_transfer.

Audited 2026-09-26 · audit v0.4.1 · source sha aec5fe0ad2ddfull audit observations/trust-audit/mcp-server/tencentcloudbase__cloudbase-ai-toolkit.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-26aec5fe0ad2ddBLOCKF23first audit
06

Questions

What is the CloudBase AI ToolKit MCP server?

Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP.

What tools does CloudBase AI ToolKit expose?

28 in total: 27 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is CloudBase AI ToolKit safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (23/100) and found 16 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does CloudBase AI ToolKit need?

It reads CB_SECRET_ID, CB_SECRET_KEY, CLAWDHUB_TOKEN, CLOUDBASE_APIKEY, CLOUDBASE_API_KEY, CLOUDBASE_PUBLISHABLE_KEY, CLOUDBASE_SECRET_ID, CLOUDBASE_SECRET_KEY, CNB_PASSWORD, CNB_TOKEN, GITHUB_TOKEN and GIT_AUTHOR_EMAIL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does CloudBase AI ToolKit run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as test-func at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (aec5fe0ad2dd), read on 2026-09-26. The repository is watched and re-audited when it changes.

Advertisement