Atlas / Skills / tencentcloudbase / CloudBase-AI-Toolkit

CloudBase-AI-ToolkitBLOCK

skills/tencentcloudbase/cloudbase-ai-toolkit

Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP.

Verdict
BLOCK
Grade
F
Trust score
23 /100
Version
2.25.10
Hosts
8 documented
License
MIT
Stars
1,114
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

CloudBase AI ToolkitAI writes the code. CloudBase runs the backend.The CloudBase integration layer for AI coding tools: Plugin installs the stack, Skills steer how code is written, MCP operates databases, functions, storage, and deploys from chat.English · 简体中文 · [Docs][docs] · [Changelog][changelog] · [Issues][github-issues-link][![][npm-version-shield]][npm-link][![][npm-downloads-shield]][npm-link][![][github-stars-shield]][github-stars-link][![][github-forks-shield]][github-forks-link][![][github-issues-shield]][github-issues-link]![][github-license-shield]![][github-contributors-shield][![][cnb-shield]][cnb-link][![][deepwiki-shield]][deepwiki-link]## Recent updatesv2.34.x (2026-09)- i18n / IDE: full tool-copy localization with an instance-level lang, plus auth site / region params so international-site login and region routing resolve correctly- Cloud API: callCloudApi service allowlist widened to 57 with built-in version mapping (multi-version services such as tke / mongodb / vod require an explicit version)- Deploy / Env: new appBuild tool with hosting build neutralization; queryEnv reports the region actually applied and domains honors a passed envId- Skills / Docs: skill fallback reads now point at the official distribution repo with a references address list; SDK-first database decision gate for cloudrun; site doc links moved to the current Markdown addresses; post-deployment share offered after delivery in the expert packs and the deploy skills (opt-in, redacted, at most once)- Deploy / Apps: the cloud upload channel now completes end to end (deployApp accepts the timestamp getUploadUrl returns, getBuildLog accepts the build ID a deploy returns), and gateway route creation verifies the upstream exists before writin

Read from source at commit 3fc83144ac26OBSERVED · 2026-09-18
02

Install

Commands as the repository documents them. They are shown, not run.

npm install @supabase/supabase-js
git clone https://github.com/InsForge/InsForge.git
git clone [email protected]:binggg/cloudbase-mcp-specs-archive.git ~/Projects/cloudbase-mcp-specs-archive
git clone https://github.com/TencentCloudBase/CloudBase-AI-ToolKit.git
npm i -g @cloudbase/cli && tcb ai
npm i -g @cloudbase/cli && tcb ai
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
claude-desktopmentioned
codexmentioned
copilotmentioned
cursormentioned
gemini-climentioned
openclawmentioned
windsurfmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---name: ai-model-nodejsdescription: "Use this skill for Node.js backend AI via @cloudbase/node-sdk (>=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration. The only SDK supporting image generation (ai.createImageModel + generateImage). Text via ai.createModel with groups cloudbase, hunyuan-exp, or custom-*; model ids (e.g. deepseek-v4-flash, glm-5, kimi-k2.6) go in the `model` field of generateText/streamText. MUST run two-step preflight before code — see body. NOT for browser/Web (use ai-model-web) or Mini Program (use ai-model-wechat)."version: 2.34.4alwaysApply: false---## Sibling skills (local only)Sibling CloudBase skills ship beside this skill. Use local relative paths such as `../auth-tool-cloudbase/SKILL.md`.If a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do **not** HTTP-fetch remote skill or protocol markdown into the agent context.## When to use this skillUse this skill for **calling AI models from Node.js backends, cloud functions, or CloudRun services** via `@cloudbase/node-sdk`.> 🧭 **Runtime-plane fit.** This is the right skill when the AI call truly belongs on the server: image generation (the only SDK that supports it), long-running agent jobs, orchestration across multiple tools, scheduled tasks, or flows that must keep secrets server-side. **If the user is building a Web page / frontend AI chat UI, do NOT wrap this SDK behind a backend proxy** — route to `ai-model-web` and call the model directly from the browser. For WeChat Mini Programs use `ai-model-wechat`. Routing is decided by runtime plane first; the concrete model (`deepseek-*`, `glm-*`, `hunyuan-*`, `kimi-*`, ...) only affects the `model` field.**Use it when you need to:**- Integrate AI text generation into a backend service- Generate images with the Hunyuan Image model- Call AI models from CloudBase cloud functions or CloudRun- Do server-side AI processing (agent orchestration, batch jobs, scheduled tasks)**Do NOT use for:**- Browser/Web apps → use the `ai-model-web` skill- WeChat Mini Program → use the `ai-model-wechat` skill- Runtimes without a CloudBase SDK (Python, Go, PHP, curl, etc.) → use the `http-api-cloudbase` skill (it now includes the `ai_model` OpenAPI spec for direct HTTP calls to the AI model endpoint; do NOT wrap this SDK behind an HTTP proxy)---## ⛔ STOP — `ai.createModel(...)` argument is **not** a vendor / model nameRead this before writing any `createModel(...)` line. Agents frequently hallucinate this argument. There are **exactly three** legal shapes. Anything else is a bug.| ✅ Legal `ai.createModel(...)` argument | When to use it ||----------------------------------------|----------------|| `"cloudbase"` | **The main managed group for server-side projects** (TokenHub-backed, multi-vendor pool). Vendor + concrete model go into the **`model` field** of `generateText` / `streamText`, e.g. `{ model: "deepseek-v4-flash" }`. **No model is enabled by default — always check `DescribeAIModels` first and, if the target model is missing, enable it with `UpdateAIModel` before calling the SDK.** || `"hunyuan-exp"` | Only if `DescribeAIModels` explicitly returns this legacy builtin group for the current env. || `"custom-<your-name>"` | A user-defined GroupName you onboarded via `CreateAIModel`. **Must** start with `custom-` (e.g. `custom-kimi`, `custom-openai-compat`). |> Image generation is a separate entry point: `ai.createImageModel("hunyuan-image")`. Do not mix it with `createModel(...)`.### ❌ Wrong argument patternsAnything that is not one of the three legal values above: vendor names (`"deepseek"`, `"glm"`, `"kimi"`, `"openai"`, `"moonshot"`, ...), concrete model ids (`"deepseek-v4-flash"`, `"hunyuan-2.0-instruct-20251111"`), the bare placeholder `"custom"`, or a variable holding the model id. All of these are bugs in `createModel(...)`.### ✅ Correct pattern — GroupName vs Model are two different fields```jsconst model = ai.createModel("cloudbase");          // ← GroupNameawait model.generateText({  model: "deepseek-v4-flash",                       // ← concrete model id  messages: [...]});```### Decision procedure (when the user names a specific model)1. The user says "use DeepSeek v3.2" / "use hunyuan instruct" / "use Kimi k2.6" / "use GLM-5" / ...2. `createModel("cloudbase")` stays the same.3. Put the model id into the **`model` field**: `{ model: "deepseek-v3.2" }`, `{ model: "hunyuan-2.0-instruct-20251111" }`, `{ model: "kimi-k2.6" }`, `{ model: "glm-5" }`, ...4. **Never assume the model is already enabled.** Before calling the SDK, verify it is present in `DescribeAIModels({ GroupName: "cloudbase" }).Models[]`. If missing, call `DescribeManagedAIModelList` to confirm the exact `Model` name the platform supports (case-sensitive — do **not** guess the spelling) and then enable it via `UpdateAIModel` with `Status: 1` (remember `Models` is a full replacement).> If you are about to type `ai.createModel(` and the thing inside the parentheses is a vendor name, a model name, or a guess — **stop**. It is almost certainly one of the three legal values above.---## Mandatory Two-Step Preflight (before any SDK code)Before calling any AI API on the server, **run the two-step preflight**: 1 eligibility, 2 group readiness. **Text generation and image generation draw from the same Token Credits resource pack**, and both must complete the preflight before code is emitted.### Step 0: obtain the environment IDCall the MCP tool `queryEnv` with `action=info` and read `EnvId` from the response.---### Preflight 1 — Eligibility (Token Credits resource pack)Call the MCP tool:```callCloudApi(service="tcb", action="DescribeEnvPostpayPackage", params={ EnvId })```**Pass conditions (all required):**- `envPostpayPackageInfoList` contains at least one entry- That entry's `postpayPackageId` starts with `pkg_tcb_tokencredits_`- That entry's `status` is NOT in `
05

Trust audit

BLOCKgrade F · trust 23/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (10 observation(s))
Shell
declared (11 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
config/.claude/skills/ai-model-nodejs/SKILL.md:257
1. **Run the two-step preflight before writing business code** — 1 eligibility: `queryEnv` → `callCloudApi(tcb, DescribeEnvPostpayPackage)` to confirm the Token Credits resource pack (text + image sha
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
config/source/skills/ai-model-nodejs/SKILL.md:257
1. **Run the two-step preflight before writing business code** — 1 eligibility: `queryEnv` → `callCloudApi(tcb, DescribeEnvPostpayPackage)` to confirm the Token Credits resource pack (text + image sha
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/build-allinone-skill.ts:140
const data = yaml.load(yamlContent) as { scenarios?: Record<string, any>[] };
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/build-skill-manifest.mjs:34
frontmatter: yaml.load(match[1]) || {},
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/check-prompts-sync.mjs:154
const config = yaml.load(fs.readFileSync(CONFIG_FILE, 'utf8'));
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/generate-prompts-data.mjs:27
const config = yaml.load(configContent);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/generate-prompts.mjs:35
frontmatter = yaml.load(frontmatterText) || {};
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/sync-cloudbase-plugin-skills.mjs:93
exec(`git clone --depth 1 --branch ${ref} ${repo} ${tmpDir}`, {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
mcp/src/interactive-server.ts:44
"metadata.google.internal",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
config/.claude/skills/ai-model-web/SKILL.md:226
> - **Enabling / configuring login providers** (phone SMS, email, WeChat Open Platform, username+password, OAuth, ...) → follow the **`auth-tool-cloudbase`** skill (backend config via `callCloudApi`).
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
config/.claude/skills/cloud-api-operations/SKILL.md:48
- Read the current credential scope from `auth` tools: `credential_scope: account` = account-level, reaches control-plane APIs subject to that identity's CAM policies; `env` = API Key, scoped to one e
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
config/.claude/skills/postgresql-development-cloudbase/SKILL.md:80
3. **Understand PG roles before writing code:** Publishable Key maps to `anon`; a logged-in user's access token maps to `authenticated`; API Key maps to `service_role` and bypasses RLS. Never expose A
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
config/.claude/skills/cloud-functions/SKILL.md:103
When `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action="getFunctionDeployStatus"` and that `taskId`; continue while the status 
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
config/source/skills/cloud-functions/SKILL.md:103
When `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action="getFunctionDeployStatus"` and that `taskId`; continue while the status 
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
doc/prompts/cloud-functions.mdx:141
When `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action="getFunctionDeployStatus"` and that `taskId`; continue while the status 
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
plugin/cloudbase/skills/cloud-functions/SKILL.md:103
When `wait=false` returns a `taskId`, the deployment workflow is not complete. Automatically call `queryFunctions` with `action="getFunctionDeployStatus"` and that `taskId`; continue while the status 
Why it matters. asks the agent to act without the user's knowledge
MEDIUMInventory / provenance · inv.binary · CWE-1104
.codebuddy/.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
.codebuddy/worktrees/.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/api-contract-review
.agents/skills/api-contract-review
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/cloud-api-recipe-authoring
.agents/skills/cloud-api-recipe-authoring
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/codebuddy-ide-mcp-upgrade
.agents/skills/codebuddy-ide-mcp-upgrade
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/doc-freshness-review
.agents/skills/doc-freshness-review
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills/docs-workflows
.agents/skills/docs-workflows
Why it matters. link not followed
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
mcp/src/utils/telemetry.ts:211
await this.postFetch('https://otheve.beacon.qq.com/analytics/v2_upload', payload);
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
plugin/cloudbase/hooks/plugin-telemetry.mjs:33
var BEACON_UPLOAD_URL = "https://otheve.beacon.qq.com/analytics/v2_upload";

Gates applied: critical_finding, instruction_override, no_behavioural_pass, undeclared_transfer.

Audited 2026-09-18 · audit v0.4.0 · source sha 3fc83144ac26full audit observations/trust-audit/skill/tencentcloudbase__cloudbase-ai-toolkit.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-183fc83144ac26BLOCKF23first audit
07

Questions

What does the CloudBase-AI-Toolkit skill do?

Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP.

Is CloudBase-AI-Toolkit safe to install?

No — not without reading the findings first. The audit graded it F (23/100) and found 16 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What can CloudBase-AI-Toolkit access on my machine?

The audit observed that it reaches the network, runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: found — see the findings.

Which assistants does CloudBase-AI-Toolkit work with?

Its documentation mentions claude-code, claude-desktop, codex, copilot, cursor, gemini-cli, openclaw and windsurf. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (3fc83144ac26), read on 2026-09-18. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement