Versioned security assessment

Report ID: SA-24B2FE42

7/9/2026, 5:00:02 PM

web-development security assessment v1

Skill Security Certification Report

Audit History
Audit model: codex Historical report
Skill name
web-development
Version
v1
Maintainer
tencentcloudbase
Coverage
3 Files scanned · 471 Lines analyzed
Policy version
Unavailable

Highest confirmed finding severity

High

4 confirmed security findings require attention.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Most static findings are false positives caused by Markdown inline code, documentation URLs, and fixed sibling-skill paths. Confirmed risks involve unpinned remote instruction URLs and a public frontend access-key example. Semantic findings also identify unsafe token-cookie and credentialed CORS guidance.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Not attestable

The required immutable binding is incomplete.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

3 Files scanned · 471 Lines analyzed

12 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Binding unavailable

  2. Artifact

    Identity incomplete

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 6 evidence locations

Filesystem access

May read or write local files.

Observed in 2 evidence locations

Env variables

May read values from the process environment.

Observed in 5 evidence locations

External commands

May invoke commands or programs outside the Skill.

Observed in 48 evidence locations

Capability review items (8)
High
Environment variable access (dot notation)
accessKey: process.env.NEXT_PUBLIC_CLOUDBASE_ACCESS_KEY!,
The example reads a variable named NEXT_PUBLIC_CLOUDBASE_ACCESS_KEY in browser initialization. NEXT_PUBLIC values are exposed to the client, so a secret access key would leak.
High
Environment variable object
accessKey: process.env.NEXT_PUBLIC_CLOUDBASE_ACCESS_KEY!,
The example reads a variable named NEXT_PUBLIC_CLOUDBASE_ACCESS_KEY in browser initialization. NEXT_PUBLIC values are exposed to the client, so a secret access key would leak.
Low
Hardcoded URL
- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk
The skill points agents to raw remote instruction content on an unpinned main-branch URL. This is legitimate documentation, but it creates a mutable external dependency after audit.
Low
Hardcoded URL
- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai
The skill points agents to raw remote instruction content on an unpinned main-branch URL. This is legitimate documentation, but it creates a mutable external dependency after audit.
Low
Hardcoded URL
- Change Safety Protocol: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/
The skill points agents to raw remote instruction content on an unpinned main-branch URL. This is legitimate documentation, but it creates a mutable external dependency after audit.
Low
Hardcoded URL
- Deployment Gate: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/
The skill points agents to raw remote instruction content on an unpinned main-branch URL. This is legitimate documentation, but it creates a mutable external dependency after audit.
Low
Hardcoded URL
- Login flow -> `../auth-tool/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/cloudb
The skill points agents to raw remote instruction content on an unpinned main-branch URL. This is legitimate documentation, but it creates a mutable external dependency after audit.
Low
Hardcoded URL
- Official Account JSAPI Pay, Native QR-code Pay, or WeChat OAuth on CloudBase -> `../cloudbase-wech
The skill points agents to raw remote instruction content on an unpinned main-branch URL. This is legitimate documentation, but it creates a mutable external dependency after audit.

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (4)

RISK-001 High
Environment file access
accessKey: process.env.NEXT_PUBLIC_CLOUDBASE_ACCESS_KEY!,
The sample places CLOUDBASE_ACCESS_KEY in a NEXT_PUBLIC variable, which Next.js exposes to browser bundles. If the value is a secret key, users following the sample leak credentials.
RISK-002 High
Client-Side Token Cookie Guidance
The Next.js example writes a session access token with document.cookie and later reads it from a request cookie. A JavaScript-readable token cookie is exposed to XSS and omits Secure, HttpOnly, and SameSite protections.
The example directly stores data.session.access_token in document.cookie and then reads cloudbase_token from request cookies. The security weakness follows from the documented flow.
RISK-003 Medium
Permissive Credentialed CORS Example
The NestJS sample allows an origin fallback of * while credentials are enabled. This can teach deployments to combine credentialed requests with overly broad origins.
The CORS example shows a wildcard origin fallback and credentials enabled in the same configuration block. This is a clear unsafe deployment pattern.
RISK-004 Medium
Mutable Remote Instruction Dependency
The standalone instructions tell agents to use raw main-branch URLs for protocols and sibling skills. Unpinned remote instructions can change after marketplace review and alter agent behavior.
The URLs are explicit raw references to main-branch skill and protocol content. The risk is mutable remote instruction loading, not a generic hardcoded URL.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    High
    Public access key example
    Remove NEXT_PUBLIC_CLOUDBASE_ACCESS_KEY from browser samples or label it only as a publishable key. Keep secret access keys server-side.
  2. FIX-002
    High
    Client-side session token cookie
    Do not store access tokens with document.cookie. Use HttpOnly, Secure, SameSite cookies set server-side or a documented SDK session mechanism.
  3. FIX-003
    Medium
    Credentialed wildcard CORS guidance
    Replace wildcard fallback with an explicit allowlist and disable credentials unless origin validation is strict.
  4. FIX-004
    Medium
    Unpinned remote instruction references
    Bundle referenced protocols or pin remote URLs to immutable commit hashes and verify content before use.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: not_attestable