volcengine-tls-logcollector

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download installation packages (e.g., logcollector.tgz, logcollector.sh) from official vendor subdomains under volces.com, which is the object storage service for Volcengine.
  • [REMOTE_CODE_EXECUTION]: Instructions describe downloading scripts and binaries from vendor infrastructure and executing them locally (e.g., /tmp/logcollector.sh install). This is handled through explicit manual steps and is consistent with standard installation workflows for the service.
  • [COMMAND_EXECUTION]: Utilizes the volclog CLI (via the ve wrapper), kubectl, and helm to manage cloud resources, Kubernetes workloads, and validate collector configurations. The skill emphasizes dry-runs and diagnostic commands (volclog doctor).
  • [PRIVILEGE_ESCALATION]: Directs the use of sudo for installing the LogCollector binary and managing its systemd service (logcollectord.service). Root privileges are required for system-level log collection.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides tools to search and preview log data (log.search, log.preview), which constitutes an untrusted data ingestion surface.
  • Ingestion points: Data from log.search results and log.preview samples, as well as the raw log streams being collected.
  • Boundary markers: Encourages use of explicit time intervals and Topic IDs to limit context.
  • Capability inventory: Shell command execution via kubectl, helm, and sudo; network interaction via vendor-provided CLI tools.
  • Sanitization: Implements a validation workflow (references/config-validation.md) to verify regex and delimiter behavior against representative samples before rules are applied.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 10:02 AM
Security Audit — agent-trust-hub — volcengine-tls-logcollector