volcengine-tls-logcollector
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download installation packages (e.g., logcollector.tgz, logcollector.sh) from official vendor subdomains under volces.com, which is the object storage service for Volcengine.
- [REMOTE_CODE_EXECUTION]: Instructions describe downloading scripts and binaries from vendor infrastructure and executing them locally (e.g., /tmp/logcollector.sh install). This is handled through explicit manual steps and is consistent with standard installation workflows for the service.
- [COMMAND_EXECUTION]: Utilizes the volclog CLI (via the ve wrapper), kubectl, and helm to manage cloud resources, Kubernetes workloads, and validate collector configurations. The skill emphasizes dry-runs and diagnostic commands (volclog doctor).
- [PRIVILEGE_ESCALATION]: Directs the use of sudo for installing the LogCollector binary and managing its systemd service (logcollectord.service). Root privileges are required for system-level log collection.
- [INDIRECT_PROMPT_INJECTION]: The skill provides tools to search and preview log data (log.search, log.preview), which constitutes an untrusted data ingestion surface.
- Ingestion points: Data from log.search results and log.preview samples, as well as the raw log streams being collected.
- Boundary markers: Encourages use of explicit time intervals and Topic IDs to limit context.
- Capability inventory: Shell command execution via kubectl, helm, and sudo; network interaction via vendor-provided CLI tools.
- Sanitization: Implements a validation workflow (references/config-validation.md) to verify regex and delimiter behavior against representative samples before rules are applied.
Audit Metadata