Cloudsmith
for LuumenAI

Read-only access to Cloudsmith packages, repositories, and audit events

Ask about an artifact and get an answer from Cloudsmith itself. Look up package metadata, checksums, and security state with CLOUDSMITH_GET_PACKAGE, scan a repository with CLOUDSMITH_LIST_REPOSITORY_VULNERABILITIES, check storage and bandwidth with CLOUDSMITH_GET_QUOTA, or trace a change through CLOUDSMITH_SEARCH_AUDIT_LOG. Connect with an API key. Access is read-only, so nothing in your repositories changes.

The Cloudsmith toolbox

10 tools, all read-only. They answer instantly, and every call is logged.

  • ReadGet Current UserReturn the identity authenticated by the connected Cloudsmith API key.
  • ReadGet PackageGet metadata, status, checksums, licensing, and security state for one package in a Cloudsmith repository.
  • ReadGet QuotaReturn current storage and bandwidth usage and allowances for a Cloudsmith namespace without inferring a billing plan name.
  • ReadGet Rate LimitsReturn Cloudsmith's current per-resource request limits, remaining counts, intervals, and throttling state for the authenticated principal.
  • ReadGet RepositoryGet configuration, visibility, usage, and capability details for one Cloudsmith repository without returning repository signing keys or certificates.
  • ReadList OrganizationsList Cloudsmith organizations associated with the authenticated principal so an agent can discover namespace slugs for later calls.
  • ReadList Repository VulnerabilitiesList vulnerability scan summaries for packages in a Cloudsmith repository.
  • ReadSearch Audit LogSearch paginated audit events for a Cloudsmith namespace by event, actor, or timestamp text.
  • ReadSearch PackagesSearch packages in a Cloudsmith repository by name, filename, version, distribution, architecture, format, or status.
  • ReadSearch RepositoriesSearch and list repositories within a Cloudsmith namespace, returning identifiers and summary state without repository signing keys.

Questions

How does LuumenAI connect to Cloudsmith?

Authorize once with API token. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.

Can LuumenAI change things in Cloudsmith on its own?

No. Every one of the 10 tools LuumenAI has for Cloudsmith is read-only, so it can answer questions from Cloudsmith but cannot change anything in it. Reads are not gated — they answer immediately, and each one is recorded on the audit trail with the actor and the result.

Who gets access to the integration?

You decide. Access is granted per agent, skill, and team, and per environment — production is not staging.

Is there an audit trail?

Every call to Cloudsmith is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.

Put Cloudsmith to work with Luumen

Connect in minutes. Every action scoped, approved, and audited from day one.