volcengine-cli

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the installation of the Volcengine CLI from official sources, including the npm registry (@volcengine/cli) and GitHub releases. These are legitimate vendor-provided tools required for the skill's functionality.
  • [COMMAND_EXECUTION]: The skill relies on executing shell commands using the ve CLI and provided Python scripts to query and modify cloud infrastructure. It implements a safety classification system requiring user confirmation for all write and destructive operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves data from Volcengine APIs (e.g., resource descriptions, API documentation) and presents it to the agent. This represents an attack surface for indirect prompt injection if an attacker can control the content of cloud resource metadata returned by the API.
  • Ingestion points: Data is ingested from the output of the ve command and the fetch_swagger.py and find_api.py scripts in SKILL.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands within the API responses are provided.
  • Capability inventory: The agent has access to Bash for command execution and Write for file modifications.
  • Sanitization: There is no evidence of sanitization for strings returned by the remote APIs before they are processed by the agent.
  • [CREDENTIALS_UNSAFE]: The skill manages Volcengine access keys and secret keys. It provides instructions for setting these via environment variables or a configuration file template. Notably, it includes explicit prohibitions against the agent reading existing configuration files that might contain actual secrets, effectively mitigating credential exposure risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 08:18 AM
Security Audit — agent-trust-hub — volcengine-cli