Back to skill

Security audit

Volcengine Compliance

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Volcengine compliance helper whose cloud write actions and local report files are disclosed and tied to its stated purpose.

Install only in an environment where the Volcengine CLI is trusted and scoped to the intended account. Review dry-runs before adding --confirm, especially when enabling the recorder or creating rules, and protect or delete generated report files if they contain sensitive inventory details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill declares no explicit permissions, yet its documented behavior includes shell execution and file generation, and also supports state-changing operations via CLI commands. This creates a permission-transparency gap: reviewers or policy engines may treat the skill as lower risk than it is, increasing the chance of unintended execution in environments that rely on declared permissions.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The skill description understates and inconsistently describes its real behavior: it can enable the configuration recorder, which changes account state, while also claiming custom-rule authoring/registration as a core capability without clear implementation boundaries. Behavior-description mismatch is dangerous because users and orchestration layers may consent to a 'compliance reporting' skill without realizing it can perform additional write operations in the target cloud account.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The overview workflow writes Markdown, CSV, and JSON artifacts containing account IDs, resource IDs, regions, and annotations to disk, defaulting to a temporary directory when none is specified. In multi-user or poorly controlled environments, these files can persist longer than expected and expose potentially sensitive inventory and compliance data to other local users, backup systems, or later processes.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.