volcengine-api

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches API documentation and search results from official Volcengine domains (api.volcengine.com). These endpoints provide the authoritative Swagger/OpenAPI specifications and metadata used to answer user queries. As these resources belong to the vendor, they are considered standard functional components.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external API responses, which presents a potential surface for indirect prompt injection.
  • Ingestion points: API metadata, Swagger specifications, and search results are retrieved from https://api.volcengine.com and integrated into the agent context (SKILL.md, Step 2).
  • Boundary markers: The instructions lack explicit technical delimiters (like XML tags or unique markers) for external content, though they advise the agent to "extract the information the user needs rather than dumping the entire Swagger."
  • Capability inventory: No dangerous capabilities such as file system modification, arbitrary command execution, or non-vendor network operations were detected in the provided files.
  • Sanitization: There is no evidence of specific sanitization or filtering logic for the content retrieved from the API Explorer endpoints beyond field selection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:16 PM
Security Audit — agent-trust-hub — volcengine-api