volcengine-knowledge-search

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill specifies the installation of the official @volcengine/cli package from the npm registry to provide the required ve binary. This resource is provided by the skill's vendor and is appropriate for the stated functionality.
  • [COMMAND_EXECUTION]: The skill uses the ve command-line tool to interact with documentation services. The usage patterns (search and fetch) are standard, well-documented, and do not involve shell injection or privilege escalation.
  • [INDIRECT_PROMPT_INJECTION]: As the skill ingests content from external web pages (official documentation), it is theoretically exposed to indirect prompt injection. However, the skill provides explicit instructions to the agent to rely on evidence and follow structured processing, which is standard for documentation retrieval tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:49 AM
Security Audit — agent-trust-hub — volcengine-knowledge-search