skills/vm0-ai/vm0-skills/doubao/Gen Agent Trust Hub

doubao

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill follows secure practices by managing API keys through environment variables (DOUBAO_API_KEY) and utilizing a dedicated connector service for configuration, rather than hardcoding secrets.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with official, well-known API endpoints operated by Volcengine and ByteDance (openspeech.bytedance.com). These network operations are intrinsic to the skill's primary function of providing voice processing services.
  • [COMMAND_EXECUTION]: The instructions utilize standard system utilities such as curl, uuidgen, and python3. The included Python script for decoding audio data is transparent, uses only standard libraries (json, base64), and performs local file operations in /tmp/ for temporary storage.
  • [DATA_EXFILTRATION]: Network traffic is directed only to the service's official API endpoints. No evidence of unauthorized data transfer to unknown or suspicious domains was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 01:52 AM
Security Audit — agent-trust-hub — doubao