arkcli-config
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill facilitates the management of local configuration for 'arkcli', a legitimate utility provided by the vendor 'volcengine'. All external resources, such as API endpoints (e.g., ark.cn-beijing.volces.com), trace back to the vendor's own infrastructure.- [SAFE]: Protective measures are explicitly defined for destructive operations. The agent is instructed to confirm user intent and reiterate the impact before executing commands like 'arkcli profile delete' or 'arkcli config reset' to prevent accidental data loss.- [SAFE]: The software update mechanism ('automatic' mode) is described with multiple security checkpoints, including staged rollout cohorts, integrity checks (SRI/tarball validation), and explicit consent requirements for new installations.- [SAFE]: Credential management instructions emphasize the use of official vendor tools ('arkcli auth logout') and recognize standard security locations like '$HOME/.arkcli/.env' for local tokens, ensuring secrets are handled appropriately.- [SAFE]: The skill correctly prioritizes configuration sources (flags > environment variables > config files), which aligns with industry best practices for CLI tools and ensures predictable behavior during troubleshooting.
Audit Metadata