Cloudinary
SkillMediaManage Cloudinary media: upload images and videos, list and inspect assets, update metadata, delete assets, and check plan usage. Trigger phrases: cloudinary, upload image, cloudinary usage.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Cloudinary skill
What this skill tells your AI
The instructions your AI receives, as published by anil-matcha/awesome-muse-connectors in connectors/cloudinary/SKILL.md and read by ahel’s review.
Purpose
Manage media on Cloudinary through the Upload and Admin APIs: upload images and videos, list and inspect assets, update metadata and tags, delete assets, and check plan usage (credits, storage, bandwidth, transformations).
Tooling
All commands go through bin/cloudinary.py:
bin/cloudinary.py auth # verify the connection (also shows plan usage)
bin/cloudinary.py usage # plan usage: credits, storage, bandwidth, transformations
bin/cloudinary.py upload --file ./photo.jpg # upload an image
bin/cloudinary.py upload --file ./clip.mp4 --resource-type video # upload a video
bin/cloudinary.py upload --file ./photo.jpg --folder products # upload into a folder
bin/cloudinary.py list --prefix products/ --max-results 20 # list image assets
bin/cloudinary.py get --public-id products/photo1 # asset details
bin/cloudinary.py update --public-id products/photo1 --data '{"tags":["summer"],"context":{"caption":"Beach"}}'
# update metadata/tags (raw JSON body, per Cloudinary docs)
bin/cloudinary.py delete --public-id products/photo1 # delete an asset
Auth
- Provider id:
cloudinary(credential is collected ascustom.cloudinary) - Collection: via the secure credential flow (
credentials.request_api_access) as a single colon-joined valuecloud_name:api_key:api_secret; the three parts come from the Cloudinary Console at Settings, API Keys. The collection step stores them as three named entries (cloud_name,api_key,api_secret) undercustom.cloudinary; the CLI splits them at use:cloud_namegoes into the request host, andapi_key:api_secretgo into the HTTP Basic auth header. - Required scopes: n/a (account API key pair)
- Allowed hosts:
api.cloudinary.com - Status check:
bin/cloudinary.py auth - Wire format (verbatim from Cloudinary's docs):
Authorization: Basic base64(api_key:api_secret)againsthttps://api.cloudinary.com/v1_1/{cloud_name}.
Operating Rules
- The free plan is credit-based across storage/bandwidth/transformations: run
usagebefore heavy work and stay inside the plan. - Confirm with the user before uploading (it consumes bandwidth/transformation quota) and before deleting (deletes are permanent).
- Never exfiltrate the credential: the CLI only ever handles surrogates. Do not print, log, or transmit the key, secret, or cloud name values.
Files
- SKILL.md
- bin/cloudinary.py
Maturity
🧪 Draft: written from Cloudinary's public Upload and Admin API docs; not yet live-tested end to end. The three-part credential split (single collected value, split into entries at use) is the design assumption to re-verify on first live run.
Signals
- GitHub stars
- 1k
- Forks
- 281
- Last commit
- Sep 2026
ahel review
K2info
exfiltration
Automated review, not a security audit. Ruleset v1+k2.
Advanced
- Item type
- skill
- Key
cloudinary- Source
- github.com/anil-matcha/awesome-muse-connectors