volcengine-troubleshooting

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is authored by 'volcengine' and exclusively utilizes official vendor tools (ve, tosutil) and official Python SDKs. It includes strict internal policies to prevent the exfiltration or logging of sensitive authentication materials, such as SecretKeys and SessionTokens.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an inherent vulnerability surface for indirect prompt injection due to its diagnostic nature, though it is assessed as safe within its primary use case.
  • Ingestion points: The skill ingests data from cloud API responses, including resource descriptions, tags, and ECS console logs (e.g., as described in references/domain-guides/compute-container-network/references/03-login-os-access/README.md).
  • Boundary markers: Absent. The instructions do not define specific delimiters to separate untrusted external content from agent instructions.
  • Capability inventory: The skill is capable of executing shell commands via subprocesses to run the ve CLI, tosutil, and custom Python diagnostic scripts.
  • Sanitization: Absent. The skill does not explicitly sanitize or escape content retrieved from API outputs before processing it, though it does instruct the agent to summarize and filter for relevance.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:49 AM
Security Audit — agent-trust-hub — volcengine-troubleshooting