volcengine-landing-zone

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on executing shell commands via the Bash tool and Terraform local-exec provisioners to interact with the ve CLI and terraform binary. These operations are core to the skill's functionality for cloud resource management. Security is managed through identity verification steps and the use of temporary, isolated configuration profiles.
  • [DYNAMIC_EXECUTION]: The skill utilizes embedded Python scripts within Terraform local-exec blocks and external Python helpers (e.g., tos_activate.py) to handle complex API interactions and data processing. These scripts use standard Python libraries and are contained within the skill's package.
  • [SAFE]: The skill implements a robust security model for an AI agent, characterized by Hard Gates (G1-G6) that enforce user confirmation before planning or executing changes. It also adheres to workspace isolation principles and secure credential hand-off protocols, ensuring that sensitive information like initial passwords is provided through local files rather than chat history. All cloud interactions target legitimate Volcengine service endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 10:02 AM
Security Audit — agent-trust-hub — volcengine-landing-zone