volcengine-tls
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill functions by executing the
ve volclogcommand-line utility to perform log management tasks, including project creation, topic resolution, and log searching as detailed inSKILL.mdand the SOPs. - [EXTERNAL_DOWNLOADS]: The skill metadata specifies the installation of the
@volcengine/cliNode.js package from the official NPM registry to provide the necessaryvebinary. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to search and analyze log data, which represents an attack surface for indirect prompt injection if malicious instructions are embedded within the log content.
- Ingestion points: External data enters the context through
log.search,log.export, andlog.ingestcommands described across all reference files. - Boundary markers: The skill does not implement explicit LLM boundary markers for log content, but it strongly prefers structured JSON processing to minimize misinterpretation.
- Capability inventory: The skill possesses the capability to execute shell commands, read/write files via the CLI, and perform network requests through the Volcengine API.
- Sanitization: There is no explicit sanitization or filtering of log data content before it is presented to the agent.
Audit Metadata