skills/volcengine/ark-cli/arkcli-gen/Gen Agent Trust Hub

arkcli-gen

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data via text prompts and external media references, presenting an attack surface for indirect prompt injection.
  • Ingestion points: The prompt positional argument and --input parameters (supporting local and remote files/URLs) used in the arkcli +gen command across SKILL.md and references/arkcli-gen.md.
  • Boundary markers: The instructions do not mandate the use of delimiters or specific safety framing when the agent interpolates user inputs into the tool command.
  • Capability inventory: The skill is authorized to execute shell commands through the arkcli binary, enabling network-based content generation, resource resolution, and local file management.
  • Sanitization: Input validation and safety filtering are delegated to the backend platform's risk detection systems (e.g., ContentRiskBlocked, SensitiveContentDetected) as noted in the error handling section of SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 03:49 PM
Security Audit — agent-trust-hub — arkcli-gen