volcengine-cli

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the Volcengine CLI binary and associated checksums from the vendor's official CDN at cloudcache.volccdn.com. This is a legitimate installation step for the tool's intended functionality.- [REMOTE_CODE_EXECUTION]: The installation process involves downloading a shell script (install.sh) and piping it to the shell (sh). As this resource is hosted on the vendor's verified infrastructure, this pattern is considered safe within the context of the skill's operation.- [COMMAND_EXECUTION]: The skill frequently executes shell commands via the ve binary and several helper scripts (scripts/ve_login_remote.sh, scripts/call_extend_api.py) to manage cloud infrastructure and authentication sessions.- [DYNAMIC_EXECUTION]: The scripts/audit_extend_apis.py script utilizes importlib.util to dynamically load a local helper script (call_extend_api.py) for the purpose of auditing API capabilities. This behavior is restricted to local files provided within the skill package.- [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and processing data from Volcengine OpenAPIs, which constitutes an indirect prompt injection surface.
  • Ingestion points: API response data processed in SKILL.md and helper scripts.
  • Boundary markers: The skill encourages the use of structured JSON output (--output json) which aids in parsing, though it lacks explicit natural language boundary markers.
  • Capability inventory: Includes file system access, network requests to vendor APIs, and cloud resource modification via the ve command.
  • Sanitization: The skill relies on the standard JSON parsing capabilities of the underlying environment to process API responses.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 09:32 AM
Security Audit — agent-trust-hub — volcengine-cli