volcengine-find-skills

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The included Python script scripts/find_skills.py performs shell command execution by calling the npx skills utility to list, add, and verify skill installations.
  • [REMOTE_CODE_EXECUTION]: The skill is designed to download and install executable code from the volcengine/volcengine-skills repository. This behavior is consistent with the skill's primary purpose as a marketplace installer for the vendor's ecosystem, though it facilitates the introduction of new executable code into the agent's environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze summaries and keywords from the references/catalog.json file to select capabilities. This creates a surface where metadata from the catalog could potentially influence agent logic.
  • Ingestion points: The references/catalog.json file contains metadata that the agent is instructed to read and interpret (specified in SKILL.md).
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are provided for processing the catalog data.
  • Capability inventory: The script scripts/find_skills.py contains subprocess.run calls capable of executing code and modifying the system state.
  • Sanitization: No specific sanitization or validation of the natural language descriptions is performed before the agent processes them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 09:32 AM
Security Audit — agent-trust-hub — volcengine-find-skills