volcengine-find-skills
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The included Python script
scripts/find_skills.pyperforms shell command execution by calling thenpx skillsutility to list, add, and verify skill installations. - [REMOTE_CODE_EXECUTION]: The skill is designed to download and install executable code from the
volcengine/volcengine-skillsrepository. This behavior is consistent with the skill's primary purpose as a marketplace installer for the vendor's ecosystem, though it facilitates the introduction of new executable code into the agent's environment. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze summaries and keywords from the
references/catalog.jsonfile to select capabilities. This creates a surface where metadata from the catalog could potentially influence agent logic. - Ingestion points: The
references/catalog.jsonfile contains metadata that the agent is instructed to read and interpret (specified inSKILL.md). - Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are provided for processing the catalog data.
- Capability inventory: The script
scripts/find_skills.pycontainssubprocess.runcalls capable of executing code and modifying the system state. - Sanitization: No specific sanitization or validation of the natural language descriptions is performed before the agent processes them.
Audit Metadata