tos-cli

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill points to installation resources hosted on the author's official GitHub organization ("volcengine/ve-storage-uni-cli").
  • [REMOTE_CODE_EXECUTION]: Documentation suggests a standard installation method involving downloading a shell script from the vendor's GitHub releases and piping it to a shell interpreter.
  • [COMMAND_EXECUTION]: The skill executes the tos-cli command-line interface to perform storage operations such as listing, status checking, and synchronization.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection due to its interaction with external object storage.
  • Ingestion points: Output from tos-cli ls and tos-cli stat is ingested into the agent context, potentially containing untrusted metadata or file names.
  • Boundary markers: No explicit delimiters are used in the prompt instructions to isolate external tool output from the agent's core logic.
  • Capability inventory: The skill possesses the capability to perform data transfers (cp, sync) and generate presigned URLs.
  • Sanitization: The skill provides a safety reference (references/safety.md) that encourages the use of --dry-run and path quoting to prevent accidental command execution or data exposure.
Recommendations
  • HIGH: Downloads and executes remote code from: https://github.com/volcengine/ve-storage-uni-cli/releases/latest/download/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 5, 2026, 04:06 PM
Security Audit — agent-trust-hub — tos-cli