byted-interactai-guide

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for the user to install the official vendor CLI tool using the command npm install -g @volcengine/rtc-cli. This is a standard installation procedure for the product's associated tooling.
  • [COMMAND_EXECUTION]: The skill utilizes the vertc command-line interface to perform several tasks, including project initialization (vertc init), authentication management (vertc auth login), and system diagnostics (vertc doctor). These operations are integral to the stated purpose of setting up and debugging the InteractAI VoiceChat Demo.
  • [INDIRECT_PROMPT_INJECTION]: The skill has the capability to search and retrieve external documentation via the vertc docs tool. This introduces an attack surface where instructions could potentially be injected through documentation content.
  • Ingestion points: Documentation content retrieved at runtime via vertc docs fetch <doc-id> as described in references/documentation-retrieval.md.
  • Boundary markers: The skill does not explicitly define delimiters for external documentation content within the system prompt or skill body.
  • Capability inventory: The skill can execute shell commands through the vertc utility, including authentication, infrastructure initialization, and development server management.
  • Sanitization: There is no explicit sanitization or filtering applied to the retrieved documentation text before it is added to the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:26 AM
Security Audit — agent-trust-hub — byted-interactai-guide