CloudBase AI ToolKitBLOCK
Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
AI writes the code. CloudBase runs the backend.
The CloudBase integration layer for AI coding tools: Plugin installs the stack, Skills steer how code is written, MCP operates databases, functions, storage, and deploys from chat.
English · 简体中文 · [Docs][docs] · [Changelog][changelog] · [Issues][github-issues-link]
[![][npm-version-shield]][npm-link] [![][npm-downloads-shield]][npm-link] [![][github-stars-shield]][github-stars-link] [![][github-forks-shield]][github-forks-link] [![][github-issues-shield]][github-issues-link] ![][github-license-shield] ![][github-contributors-shield] [![][cnb-shield]][cnb-link] [![][deepwiki-shield]][deepwiki-link]
Recent updates
v2.34.x (2026-09)
- i18n / IDE: full tool-copy localization with an instance-level
lang, plusauthsite/regionparams so international-site login and region routing resolve correctly - Cloud API:
callCloudApiservice allowlist widened to 57 with built-in version mapping (multi-version services such astke/mongodb/vodrequire an explicitversion) - Deploy / Env: new
appBuildtool with hosting build neutralization;queryEnvreports the region actually applied anddomainshonors a passed envId - Skills / Docs: skill fallback reads now point at the official distribution repo with a references address list; SDK-first database decision gate for cloudrun; site doc links moved to the current Markdown addresses; post-deployment share offered after delivery in the expert packs and the deploy skills (opt-in, redacted, at most once)
- Deploy / Apps: the cloud upload channel now completes end to end (
deployAppaccepts the timestampgetUploadUrlreturns,getBuildLogaccepts the build ID a deploy returns), and gateway route creation verifies t
aec5fe0ad2ddOBSERVED · 2026-09-26Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add cloudbase-mcp -- npx -y @cloudbase/[email protected]
Exposed tools (28)
27 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
ai_model | read | AI 大模型接入 API - 统一 AI 模型 HTTP API |
auth | read | Authentication API - 身份认证 HTTP API |
auth-tool-cloudbase | read | Auth tool skill |
branded-skill-name | read | Synthetic mismatch for name resolution |
categoryProbe | read | |
cloudbase | read | Main entry skill |
cloudrun | read | CloudRun API - 云托管服务 HTTP API |
demo | read | |
demo-agent-top-level | read | test agent |
downloadTemplate | read | |
functions | read | Cloud Functions API - 云函数 HTTP API |
manageCloudRun | read | |
manageHosting | read | |
manageStorage | read | |
miniprogram-development | read | WeChat Mini Program skill |
mysqldb | read | MySQL RESTful API - 云开发 MySQL 数据库 HTTP API |
nosql | read | NoSQL RESTful API - 文档型数据库 HTTP API |
pgdb | write | PostgreSQL RESTful API (PostgREST) - 云开发 PostgreSQL 数据库 HTTP API,含 exec-pgsql 直连 SQL |
queryCloudRun | read | |
queryHosting | read | |
queryStorage | read | |
storage | read | Storage API - 云存储 HTTP API |
t | read | |
web-development | read | Web dev |
分析函数错误 | read | 使用 AI 分析云函数错误并修复 |
创建云函数 | read | 使用 AI 创建云函数并生成调用代码 |
创建数据库表 | read | 使用 AI 设计并创建 MySQL 数据库表结构 |
集成登录功能 | read | 使用 AI 集成身份认证功能到项目中 |
Trust audit
BLOCKgrade F · trust 23/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (11 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
1. **Run the two-step preflight before writing business code** — 1 eligibility: `queryEnv` → `callCloudApi(tcb, DescribeEnvPostpayPackage)` to confirm the Token Credits resource pack (text + image sha
const data = yaml.load(yamlContent) as { scenarios?: Record<string, any>[] };frontmatter: yaml.load(match[1]) || {},const config = yaml.load(fs.readFileSync(CONFIG_FILE, 'utf8'));
const config = yaml.load(configContent);
frontmatter = yaml.load(frontmatterText) || {};exec(`git clone --depth 1 --branch ${ref} ${repo} ${tmpDir}`, {"metadata.google.internal",
> - **Enabling / configuring login providers** (phone SMS, email, WeChat Open Platform, username+password, OAuth, ...) → follow the **`auth-tool-cloudbase`** skill (backend config via `callCloudApi`).
- Read the current credential scope from `auth` tools: `credential_scope: account` = account-level, reaches control-plane APIs subject to that identity's CAM policies; `env` = API Key, scoped to one e
3. **Understand PG roles before writing code:** Publishable Key maps to `anon`; a logged-in user's access token maps to `authenticated`; API Key maps to `service_role` and bypasses RLS. Never expose A
When `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action="getFunctionDeployStatus"` and that `taskId`; continue while the status
When `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action="getFunctionDeployStatus"` and that `taskId`; continue while the status
When `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action="getFunctionDeployStatus"` and that `taskId`; continue while the status
When `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action="getFunctionDeployStatus"` and that `taskId`; continue while the status
When `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action="getFunctionDeployStatus"` and that `taskId`; continue while the status
.DS_Store
.DS_Store
.agents/skills/api-contract-review
.agents/skills/cloud-api-recipe-authoring
.agents/skills/codebuddy-ide-mcp-upgrade
.agents/skills/doc-freshness-review
.agents/skills/docs-workflows
await this.postFetch('https://otheve.beacon.qq.com/analytics/v2_upload', payload);var BEACON_UPLOAD_URL = "https://otheve.beacon.qq.com/analytics/v2_upload";
Gates applied: critical_finding, instruction_override, no_behavioural_pass, undeclared_transfer.
aec5fe0ad2ddfull audit observations/trust-audit/mcp-server/tencentcloudbase__cloudbase-ai-toolkit.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-26 | aec5fe0ad2dd | BLOCK | F | 23 | first audit |
Questions
What is the CloudBase AI ToolKit MCP server?
Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP.
What tools does CloudBase AI ToolKit expose?
28 in total: 27 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is CloudBase AI ToolKit safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (23/100) and found 16 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does CloudBase AI ToolKit need?
It reads CB_SECRET_ID, CB_SECRET_KEY, CLAWDHUB_TOKEN, CLOUDBASE_APIKEY, CLOUDBASE_API_KEY, CLOUDBASE_PUBLISHABLE_KEY, CLOUDBASE_SECRET_ID, CLOUDBASE_SECRET_KEY, CNB_PASSWORD, CNB_TOKEN, GITHUB_TOKEN and GIT_AUTHOR_EMAIL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does CloudBase AI ToolKit run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as test-func at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (aec5fe0ad2dd), read on 2026-09-26. The repository is watched and re-audited when it changes.