tos-cli
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill points to installation resources hosted on the author's official GitHub organization ("volcengine/ve-storage-uni-cli").
- [REMOTE_CODE_EXECUTION]: Documentation suggests a standard installation method involving downloading a shell script from the vendor's GitHub releases and piping it to a shell interpreter.
- [COMMAND_EXECUTION]: The skill executes the
tos-clicommand-line interface to perform storage operations such as listing, status checking, and synchronization. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection due to its interaction with external object storage.
- Ingestion points: Output from
tos-cli lsandtos-cli statis ingested into the agent context, potentially containing untrusted metadata or file names. - Boundary markers: No explicit delimiters are used in the prompt instructions to isolate external tool output from the agent's core logic.
- Capability inventory: The skill possesses the capability to perform data transfers (
cp,sync) and generate presigned URLs. - Sanitization: The skill provides a safety reference (
references/safety.md) that encourages the use of--dry-runand path quoting to prevent accidental command execution or data exposure.
Recommendations
- HIGH: Downloads and executes remote code from: https://github.com/volcengine/ve-storage-uni-cli/releases/latest/download/install.sh - DO NOT USE without thorough review
Audit Metadata