byted-acep-api

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill enables the execution of shell commands on remote cloud phone instances through the run-command and run-sync-command tools. This is a core administrative feature explicitly documented for resource management.
  • [EXTERNAL_DOWNLOADS]: All network operations are directed towards official Volcengine API endpoints (open.volcengineapi.com) and associated edge services. These domains are recognized vendor infrastructure for the 'bytedance' author.
  • [DATA_EXFILTRATION]: The skill supports bidirectional file transfers (push-file, pull-file) between the host and managed instances. These capabilities are intended for deployment and diagnostics and are restricted to authorized vendor channels.
  • [SAFE]: Authentication is handled securely via environment variables or local configuration files, with no hardcoded secrets or credentials found in the source code. The implementation follows the principle of least privilege within the scope of the provided management tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 06:17 AM
Security Audit — agent-trust-hub — byted-acep-api