volcengine-tls

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill functions by executing the ve volclog command-line utility to perform log management tasks, including project creation, topic resolution, and log searching as detailed in SKILL.md and the SOPs.
  • [EXTERNAL_DOWNLOADS]: The skill metadata specifies the installation of the @volcengine/cli Node.js package from the official NPM registry to provide the necessary ve binary.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to search and analyze log data, which represents an attack surface for indirect prompt injection if malicious instructions are embedded within the log content.
  • Ingestion points: External data enters the context through log.search, log.export, and log.ingest commands described across all reference files.
  • Boundary markers: The skill does not implement explicit LLM boundary markers for log content, but it strongly prefers structured JSON processing to minimize misinterpretation.
  • Capability inventory: The skill possesses the capability to execute shell commands, read/write files via the CLI, and perform network requests through the Volcengine API.
  • Sanitization: There is no explicit sanitization or filtering of log data content before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 06:25 AM
Security Audit — agent-trust-hub — volcengine-tls