ve-tos-cli

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill contains instructions to install the ve-tos-cli tool using a shell script fetched from the vendor's official GitHub repository (github.com/volcengine/ve-storage-uni-cli). While piped execution to a shell is typically a high-risk pattern, this resource is owned by the skill's author and facilitates the tool's intended installation process.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of CLI commands to interact with the local filesystem and remote object storage. It mitigates risk through explicitly linked safety guidelines that advise the use of --dry-run and require clear user confirmation for destructive operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill's functionality involves processing data from external storage buckets, creating a potential surface for indirect prompt injection.
  • Ingestion points: Data is retrieved from remote buckets via commands like ls, stat, and sync (SKILL.md).
  • Boundary markers: The instructions do not define specific delimiters to isolate potentially untrusted data retrieved from external sources.
  • Capability inventory: The skill allows for file system modifications, network transfers, and local configuration updates (SKILL.md).
  • Sanitization: The safety documentation in references/safety.md explicitly mandates quoting paths and storage URIs to prevent command injection from malicious filenames or inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 09:01 AM
Security Audit — agent-trust-hub — ve-tos-cli