volcengine-cloud-trail
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes audit event logs retrieved from the Volcengine platform, which may contain attacker-controlled strings (e.g., UserAgent, ResourceID, or Error Messages). This represents a theoretical surface for indirect prompt injection.
- Ingestion points: Audit event data retrieved by
scripts/cloud_trail.pyvia the Volcengine CLI'sLookupEventsaction. - Boundary markers: Instructions in
SKILL.mdandreferences/event-query.mddirect the agent to transcribe logs using a structured JSONC format with field-level annotations. - Capability inventory: The skill possesses capabilities to create, modify, and delete audit trails and backfill delivery tasks.
- Sanitization: The Python wrapper script parses the raw CLI output as structured JSON and selects specific keys for presentation, limiting the raw data passed directly to the agent.
- [COMMAND_EXECUTION]: The skill uses a Python script (
scripts/cloud_trail.py) to execute the official Volcengine command-line interface (ve). - Execution is performed using
subprocess.runwith argument lists rather than shell strings, mitigating shell injection vulnerabilities. - The script implements an allowlist of permitted cloud actions (
ALLOWED_ACTIONS) and validates input parameters, such as time formats and pagination integers. - All write operations are protected by a pre-flight dry-run and require a user-confirmed
--confirmflag before execution. - [EXTERNAL_DOWNLOADS]: The skill configuration specifies the installation of the
@volcengine/cliNode.js package. - This package is the official tool provided by the vendor, Volcengine, and is downloaded from the standard npm registry.
- Usage of this vendor-provided resource is consistent with the skill's primary purpose of cloud management.
Audit Metadata