cloud-functions
CloudBase function runtime guide for building, deploying, and debugging your own Event Functions or HTTP Functions. This skill should be used when users need application runtime code on CloudBase, not when they are merely calling CloudBase official platform APIs.
Install / Use
npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloud-functionsInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
OperationsSupported Platforms
Our assessment of cloud-functions
cloud-functions scores 93/100 on our quality scale, 187th of 740 Operations skills we index (top 26%).
Its SKILL.md is 31 KB long, well organised into 29 sections with 7 code examples: a thorough specification that gives an agent plenty to work with.
With 1,124 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 9 days ago, so cloud-functions is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
cloud-functions compared with similar skills
All 4 of these similar skills score higher than cloud-functions; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| cloud-functions (this skill)by TencentCloudBase | 93 | 1.1k | 9d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 89.8k | 18d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.4k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.4k | today | MCP Server |
| crawl4aiby unclecode | 100 | 84.7k | 8d ago | MCP Server |
Frequently asked questions
- How do I install cloud-functions?
- Run
npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill cloud-functions. The install tabs above show the steps for each supported agent. - Which AI agents does cloud-functions work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is cloud-functions safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is cloud-functions still maintained?
- The repository was last updated 9 days ago, so cloud-functions is actively maintained.
Skill content
View source on GitHubname: cloud-functions description: CloudBase function runtime guide for building, deploying, and debugging your own Event Functions or HTTP Functions. This skill should be used when users need application runtime code on CloudBase, not when they are merely calling CloudBase official platform APIs. version: 2.34.8 alwaysApply: false
Sibling skills (local only)
Sibling CloudBase skills ship beside this skill. Use local relative paths such as ../auth-tool-cloudbase/SKILL.md.
If a referenced sibling skill file is missing from this environment, ask the user to install the full CloudBase plugin (or the missing skill). Do not HTTP-fetch remote skill or protocol markdown into the agent context.
Cross-cutting protocols (required before code changes or deployments):
- Change Safety Protocol:
../cloudbase-platform/references/protocols/change-safety-protocol.md - Deployment Gate:
../cloudbase-platform/references/protocols/deployment-gate.md - Sensitive Runtime Data Protection:
../cloudbase-platform/references/protocols/sensitive-runtime-data-protection.md
Cloud Functions Development
Activation Contract
Use this first when
- The task is to create, update, deploy, inspect, or debug a CloudBase Event Function or HTTP Function that serves application runtime logic.
- The request mentions function runtime, function logs,
scf_bootstrap, function triggers, or function gateway exposure.
Read before writing code if
- You still need to decide between Event Function and HTTP Function.
- The task mentions
manageFunctions,queryFunctions,manageGateway, or legacy function-tool names. - The task might require
callCloudApias a fallback for logs or gateway setup. - An HTTP Function will call CloudBase resources through
@cloudbase/node-sdkor@cloudbase/manager-node-> read./references/http-function-credentials.md. HTTP Functions must use explicit credentials; do not rely on the Event Function passwordless runtime path.
Exception only (do not read by default)
- Migrating an existing app that already uses classic TCP DB clients (
DATABASE_URL/ Prisma /mysql2/pg/ Redis) → read./references/vpc-and-tcp-database.mdvia./references.md. New business CRUD must prefer CloudBase native SDK (app.database()/app.rdb()) or MCP SQL tools instead of TCP.
Then also read
- Detailed reference routing ->
./references.md - Auth setup or provider-related backend work ->
../auth-tool-cloudbase/SKILL.md - CloudBase Integration Center generated WeChat Pay or Official Account functions ->
../cloudbase-wechat-integration/SKILL.md(official docs:https://docs.cloudbase.net/integration/introduce.md) - AI in functions ->
../ai-model-nodejs/SKILL.md - Long-lived container services or Agent runtimes ->
../cloudrun-development/SKILL.md - Calling CloudBase official platform APIs from a client or script ->
../http-api-cloudbase/SKILL.md
Do NOT use for
- CloudRun container services.
- Web authentication UI implementation.
- Database-schema design or general data-model work.
- CloudBase official platform API clients or raw HTTP integrations that only consume platform endpoints.
- Creating Integration Center instances through guessed APIs. For WeChat Pay or Official Account generated functions, use
cloudbase-wechat-integrationfor the business contract and this skill only for function operations. - Tasks that the CloudBase JS SDK can handle directly — simple data reads/writes, leaderboards, file uploads, real-time queries. Reach for the matching SDK surface before writing a function:
db.collection(...).get/add/updateonly for confirmed NoSQL collections, andapp.rdb().from(...)for CloudBase PG tables. Functions add deployment complexity, CORS configuration, and HTTP gateway binding that the SDK eliminates entirely.
Common mistakes / gotchas
- Picking the wrong function type and trying to compensate later.
- Confusing official CloudBase API client work with building your own HTTP function.
- Mixing Event Function code shape (
exports.main(event, context)) with HTTP Function code shape (req/reson port9000). - Treating HTTP Access as the implementation model for HTTP Functions. HTTP Access is a gateway configuration for Event Functions, not the HTTP Function runtime model.
- Assuming
db.collection("name").add(...)will create a missing document-database collection automatically. Collection creation is a separate management step. - Forgetting that runtime cannot be changed after creation.
- Using cloud functions as the first answer for Web login.
- Forgetting that HTTP Functions must ship
scf_bootstrap, listen on port9000, and include dependencies. - Assuming an HTTP Function can use CloudBase SDKs without explicit credentials. The default temporary credential path is not reliable for HTTP Functions and credential rotation can break a running service. Use a CloudBase server API Key or Tencent Cloud key pair for
@cloudbase/node-sdk; use a Tencent Cloud key pair for@cloudbase/manager-node. Seereferences/http-function-credentials.md. - Forgetting to configure function security rules after creating an HTTP Function. Default rules reject anonymous callers with
EXCEED_AUTHORITY. Note: anonymous login is disabled by default for new environments — if the function needs public access without authentication, configure the security rule to allow all callers rather than relying on anonymous login. - Mismatching the
scf_bootstrapNode.js binary path with the function runtime (e.g. using/var/lang/node18/bin/nodebut settingruntime: "Nodejs16.13"). - For Custom Image HTTP Functions: forgetting that TCR, the CloudApp build, and SCF must be in the same region; using
:latestinstead of a unique tag; or confusing the request-driven port-9000image model with a long-lived CloudRun container that listens on the injectedPORT. - Assuming MCP covers the whole image pipeline.
manageFunctionscovers SCF image deploy (Stage B) viaruntime: "CustomImage"+imageConfig, but the CloudApp custom build → TCR push (Stage A) is a raw Tencent Cloud API path — confirm action names and parameters from official docs before anycallCloudApifallback. - Making code or configuration changes without first following the Change Safety Protocol (
cloudbase-platform/references/protocols/change-safety-protocol.md). - Exposing functions publicly or deploying without first completing the checks in
cloudbase-platform/references/protocols/deployment-gate.md. - Returning
req.headers,process.env,event, orcontextwholesale — gateways may injectx-cloudbase-context(base64 temporary credentials). Never echo that header or dump credential env vars to clients. Follow../cloudbase-platform/references/protocols/sensitive-runtime-data-protection.md. - Using a bare layer name (e.g.
common) across environments. SCF LayerName is an account-scoped shared namespace: same name → shared version sequence. Create new layers with fixed format{layerName}_{当前envId}(e.g.common_cloud1-d9ghadgak3edf6b36). Pass the full name aslayerName— do not invent automatic suffixes. Treat MCP layerwarningsas soft advisories (operation still succeeds). Details:./references/operations-and-config.md. - Long-running MCP image deployments must complete the full workflow: When using
manageFunctionswithdeployFunctionfor a realcloudorlocaldeployment, preferwait=falseto avoid blocking a single Tool Call for an extended period. If the tool returns ataskId, do not end the workflow, report success, or ask the user to wait while the status isrunning. Automatically callqueryFunctions(action="getFunctionDeployStatus", taskId="...")and continue polling according to the reported progress until the status becomessucceededorfailed. Only after reaching a reasonable polling limit may you report that the deployment is still in progress; include thetaskId, current stage, and latest progress. On success, report the image URI or build ID, function status, and Gateway URL. On failure, report the failed stage, error code, request ID, and diagnostic guidance. If the status isexpired, explain that the local task record exceeded its retention window; the cloud deployment may still be running, so callgetFunctionDetailto confirm the actual cloud-side status instead of treating it as a failure.
Minimal checklist
- Read Cloud Functions Execution Checklist before deployment or runtime changes.
- Decide whether the task is Event Function, HTTP Function, or actually CloudRun.
- Pick the detailed reference file in references.md before writing implementation code.
MCP image deployment with polling
For real cloud or local custom-image deployments, prefer:
{
"action": "deployFunction",
"dryRun": false,
"confirm": true,
"wait": false,
"deployConfig": {}
}
The wait field controls whether the current MCP Tool call waits for the complete deployment:
wait=true: wait for the manager deployment to reach a terminal result and return it.wait=false: return ataskIdpromptly while the deployment continues in the MCP background.
When wait=false returns a taskId, the deployment workflow is not complete. Automatically call queryFunctions with action="getFunctionDeployStatus" and that taskId; continue while the status is running, then stop only at succeeded or failed. Wait about 5 seconds before the first follow-up query and use the returned progress/nextActions to continue without aggressive polling. Do not tell the user to ask again or imply success before a terminal status is returned. An expired status means the task exceeded the maximum retention window and was force-terminated locally — the cloud deployment may still be in progress, so confirm the real state with getFunctionDetail instead of reporting failure.
If a reasonable polling limit is reached, report only that the task is still running, including the taskId, current status, current stage, and latest progress. For a terminal result, report the deployment strategy, action, image URI/digest, build ID, function status, Gateway URL, or the failed stage, error code, request ID, and diagnostic next step.
Personal-tier TCR credentials — never put the password in tool arguments
Personal-tier image builds (imageConfig.imageType="personal" with local / cloud) need a TCR push credential. Read it from the MCP process environment, not from tool arguments:
- Leave
func.imageConfig.build.registryCredentialout of the request whenTCB_TCR_USERNAMEandTCB_TCR_PASSWORDare set in the MCP serverenvblock — the MCP fills them in automatically, the same wayTENCENTCLOUD_SECRETIDworks. - Never ask the user to paste the password into chat, and never write it into tool arguments. Anything placed in arguments enters the model context and the tool-call history.
- If deployment fails with
CLOUD_REGISTRY_CREDENTIAL_MISSINGorCLOUD_REGISTRY_CREDENTIAL_INVALID, instruct the user to add these two variables to theenvblock of their MCP configuration and restart the MCP server. Do not work around it by passing the credential inline. - The username is the Tencent Cloud account UIN and is not itself a secret; it may be passed explicitly if needed. Explicit arguments take precedence per field, so username-in-argument plus password-from-environment is a valid combination.
Know when that environment channel does not exist. It works only for a local stdio MCP server whose client configuration exposes a custom env block. Some GUI clients do not inherit shell exports, and IDE-embedded MCP servers usually inject credentials from a hard-coded allowlist (often only TENCENTCLOUD_*), leaving the user no way to set arbitrary variables. Telling those users to "set it in the MCP env block" is an instruction they cannot
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
89.8kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.4kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Scrapling
85.4k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
crawl4ai
84.7kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
