tos-cli

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill documents an installation procedure using a shell script fetched from the vendor's official GitHub repository (volcengine/ve-storage-uni-cli) and piped to the shell.- [EXTERNAL_DOWNLOADS]: The skill suggests installing the tos-cli tool via standard package managers including npm, pip, Homebrew, and Cargo, referencing official vendor channels.- [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute tos-cli commands for storage operations, metadata inspection, and configuration management.- [DATA_EXFILTRATION]: While the tool handles sensitive storage data, the skill includes explicit safety instructions in references/safety.md to avoid printing access keys, secret keys, or session tokens in logs or responses.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 05:10 PM
Security Audit — agent-trust-hub — tos-cli