volcengine-cli
Warn
Audited by Snyk on Mar 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill's helper scripts (scripts/fetch_swagger.py and scripts/find_api.py) make runtime requests to api.volcengine.com (e.g., https://api.volcengine.com/api/common/explorer and https://api.volcengine.com/api/common/search/all) to fetch OpenAPI/swagger and search results which are parsed and used to generate CLI parameter docs and commands that directly influence agent prompts/behavior, and the skill instructs using these scripts for required parameter retrieval on write operations.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata