Versioned security assessment

Report ID: SA-24B2FE42

7/9/2026, 5:00:02 PM

web-development security assessment v2

Skill Security Certification Report

Audit History
Audit model: codex Latest published report
Skill name
web-development
Version
v2.23.8
Maintainer
tencentcloudbase
Coverage
3 Files scanned · 471 Lines analyzed
Policy version
Unavailable

Highest confirmed finding severity

High

4 confirmed security findings require attention.

Installation context

Check the current Skill page

This page summarizes report evidence only. The Skill page provides the canonical install advisory.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Most static findings are false positives caused by Markdown inline code, documentation URLs, and fixed sibling-skill paths. Confirmed risks involve unpinned remote instruction URLs and a public frontend access-key example. Semantic findings also identify unsafe token-cookie and credentialed CORS guidance.

Report position

Latest published report

Latest refers to the report sequence, not to artifact currentness.

Audit attestation

Not attestable

The required immutable binding is incomplete.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

3 Files scanned · 471 Lines analyzed

12 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Commit and path bound

  2. Artifact

    Content and tree hashes bound

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 6 evidence locations

Filesystem access

May read or write local files.

Observed in 2 evidence locations

Env variables

May read values from the process environment.

Observed in 5 evidence locations

External commands

May invoke commands or programs outside the Skill.

Observed in 48 evidence locations

Capability review items (8)
High
Environment variable access (dot notation)
accessKey: process.env.NEXT_PUBLIC_CLOUDBASE_ACCESS_KEY!,
The example reads a variable named NEXT_PUBLIC_CLOUDBASE_ACCESS_KEY in browser initialization. NEXT_PUBLIC values are exposed to the client, so a secret access key would leak.
High
Environment variable object
accessKey: process.env.NEXT_PUBLIC_CLOUDBASE_ACCESS_KEY!,
The example reads a variable named NEXT_PUBLIC_CLOUDBASE_ACCESS_KEY in browser initialization. NEXT_PUBLIC values are exposed to the client, so a secret access key would leak.
Low
Hardcoded URL
- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk
The skill points agents to raw remote instruction content on an unpinned main-branch URL. This is legitimate documentation, but it creates a mutable external dependency after audit.
Low
Hardcoded URL
- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai
The skill points agents to raw remote instruction content on an unpinned main-branch URL. This is legitimate documentation, but it creates a mutable external dependency after audit.
Low
Hardcoded URL
- Change Safety Protocol: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/
The skill points agents to raw remote instruction content on an unpinned main-branch URL. This is legitimate documentation, but it creates a mutable external dependency after audit.
Low
Hardcoded URL
- Deployment Gate: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/skills/
The skill points agents to raw remote instruction content on an unpinned main-branch URL. This is legitimate documentation, but it creates a mutable external dependency after audit.
Low
Hardcoded URL
- Login flow -> `../auth-tool/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/cloudb
The skill points agents to raw remote instruction content on an unpinned main-branch URL. This is legitimate documentation, but it creates a mutable external dependency after audit.
Low
Hardcoded URL
- Official Account JSAPI Pay, Native QR-code Pay, or WeChat OAuth on CloudBase -> `../cloudbase-wech
The skill points agents to raw remote instruction content on an unpinned main-branch URL. This is legitimate documentation, but it creates a mutable external dependency after audit.

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (4)

RISK-001 High
Environment file access
accessKey: process.env.NEXT_PUBLIC_CLOUDBASE_ACCESS_KEY!,
The sample places CLOUDBASE_ACCESS_KEY in a NEXT_PUBLIC variable, which Next.js exposes to browser bundles. If the value is a secret key, users following the sample leak credentials.
RISK-002 High
Client-Side Token Cookie Guidance
The Next.js example writes a session access token with document.cookie and later reads it from a request cookie. A JavaScript-readable token cookie is exposed to XSS and omits Secure, HttpOnly, and SameSite protections.
The example directly stores data.session.access_token in document.cookie and then reads cloudbase_token from request cookies. The security weakness follows from the documented flow.
RISK-003 Medium
Permissive Credentialed CORS Example
The NestJS sample allows an origin fallback of * while credentials are enabled. This can teach deployments to combine credentialed requests with overly broad origins.
The CORS example shows a wildcard origin fallback and credentials enabled in the same configuration block. This is a clear unsafe deployment pattern.
RISK-004 Medium
Mutable Remote Instruction Dependency
The standalone instructions tell agents to use raw main-branch URLs for protocols and sibling skills. Unpinned remote instructions can change after marketplace review and alter agent behavior.
The URLs are explicit raw references to main-branch skill and protocol content. The risk is mutable remote instruction loading, not a generic hardcoded URL.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    High
    Public access key example
    Remove NEXT_PUBLIC_CLOUDBASE_ACCESS_KEY from browser samples or label it only as a publishable key. Keep secret access keys server-side.
  2. FIX-002
    High
    Client-side session token cookie
    Do not store access tokens with document.cookie. Use HttpOnly, Secure, SameSite cookies set server-side or a documented SDK session mechanism.
  3. FIX-003
    Medium
    Credentialed wildcard CORS guidance
    Replace wildcard fallback with an explicit allowlist and disable credentials unless origin validation is strict.
  4. FIX-004
    Medium
    Unpinned remote instruction references
    Bundle referenced protocols or pin remote URLs to immutable commit hashes and verify content before use.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec
Content hash
cc5d27bc9eb5abac227971755eec2b322f5619fb249578f6c233b41a0c6f03a5
Tree hash
c0f73fd435a286342510e463c9c81584cf98ab92e8173ec69fce10fbf470ee7e
Skill path
skills/tencentcloudbase/web-development
Audit payload hash
c6929d705021c6497606bda9fe809b28

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: not_attestable