Back to skill

Security audit

Volcengine TLS LogCollector

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Volcengine TLS LogCollector deployment guide with expected but high-impact cloud, Kubernetes, and host installation steps.

Install only if you intend to let an agent help configure Volcengine TLS logging with cloud credentials, Kubernetes access, and possibly root access on target hosts. Verify official installer URLs and versions, prefer vendor-supported checksum/signature checks when available, avoid exposing AK/SK in command history, and review all dry-run output before any live write or install.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (15)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language strings in the skill metadata are entirely in Chinese and provide no indication that users may choose another language. This creates a locale/language policy concern because the skill appears to enforce a specific language without explicit user opt-in or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/config-validation.md (reported line 79)May include surrounding context.

--input '{"topicId":"","delimiter":",;=|/","log":""}'

text

Do not copy delimiter examples into production without checking the actual query and tokenization requirements.

## Processor validation

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/linux-host.md (reported line 95)May include surrounding context.

--input '{"topicId":"","delimiter":",;=|/","log":""}'

text

Do not copy delimiter examples into production without checking the actual query and tokenization requirements.

## Processor validation

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/kubernetes-daemonset.md (reported line 35)May include surrounding context.

wget "https://logcollector-.tos-.volces.com/logcollector.tgz"
-O /tmp/logcollector.tgz tar -xzf /tmp/logcollector.tgz -C /tmp chmod 755 /tmp/logcollector/logcollector.sh /tmp/logcollector/logcollector.sh --help

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/linux-host.md (reported line 21)May include surrounding context.

md
Confirm:

- Linux and a package matching `x86_64/amd64` or `aarch64/arm64`
- sufficient disk, CPU, memory, file permissions, and root/sudo access
- explicit region, TLS endpoint, and public/private network path
- network reachability to the package location and TLS endpoint
- the intended host group identity: Label by default, IP only when explicitly required

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Marking a downloaded script in /tmp as executable is part of a potentially dangerous execution chain because /tmp is a shared, attacker-relevant location and the file is later run with elevated privileges. While chmod alone is not the exploit, the pattern encourages executing an untrusted network-retrieved artifact from a temporary path without strong provenance checks.

Content

Scanner excerpt · references/linux-host.md (reported line 41)May include surrounding context.

For a private network, the official guide may use the corresponding .ivolces.com domain. Validate the final URL with wget --spider or an equivalent HTTP check, then inspect what was downloaded:

bash
chmod 755 /tmp/logcollector.sh
file /tmp/logcollector.sh
/tmp/logcollector.sh --help

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

The document instructs users to execute a downloaded script from /tmp with sudo while passing cloud credentials on the command line. If the downloaded installer is tampered with, this yields immediate root-level arbitrary code execution; additionally, credentials supplied as arguments may be exposed to local process inspection or shell history tooling depending on environment.

Content

Scanner excerpt · references/linux-host.md (reported line 57)May include surrounding context.

md
read -r -s -p "TLS SecretKey: " TLS_LOGCOLLECTOR_SK
printf '\n'

sudo /tmp/logcollector.sh install \
  --region <region> \
  --endpoint <explicit-tls-endpoint> \
  --secret_id "${TLS_LOGCOLLECTOR_AK}" \

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/tls-resources.md (reported line 74)May include surrounding context.

--input '{"HostGroupName":"","HostGroupType":"Label","HostIdentifier":"","ServiceLogging":true}'

text

The installed LogCollector label must exactly match `HostIdentifier`. For an explicitly requested IP group, re-read `host-group.create`, use its current `HostGroupType` and `HostIpList` contract, and configure installation with IP identity only. Do not combine label and IP identity.

## Collector rule

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/linux-host.md (reported line 76)May include surrounding context.

Linux host:

bash
sudo systemctl is-active logcollectord.service
sudo systemctl status logcollectord.service --no-pager -l
/usr/local/logcollector/logcollector -v

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/linux-host.md (reported line 77)May include surrounding context.

Linux host:

bash
sudo systemctl is-active logcollectord.service
sudo systemctl status logcollectord.service --no-pager -l
/usr/local/logcollector/logcollector -v

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/linux-host.md (reported line 91)May include surrounding context.

Linux host:

bash
sudo systemctl is-active logcollectord.service
sudo systemctl status logcollectord.service --no-pager -l
/usr/local/logcollector/logcollector -v

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/linux-host.md (reported line 92)May include surrounding context.

Linux host:

bash
sudo systemctl is-active logcollectord.service
sudo systemctl status logcollectord.service --no-pager -l
/usr/local/logcollector/logcollector -v

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/verification.md (reported line 26)May include surrounding context.

Linux host:

bash
sudo systemctl is-active logcollectord.service
sudo systemctl status logcollectord.service --no-pager -l
/usr/local/logcollector/logcollector -v

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/verification.md (reported line 27)May include surrounding context.

Linux host:

bash
sudo systemctl is-active logcollectord.service
sudo systemctl status logcollectord.service --no-pager -l
/usr/local/logcollector/logcollector -v

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language description includes both English and Chinese, but the file does not state that the skill is intended for bilingual users or provide an explicit language preference mechanism. Under the policy, language constraints or assumptions should be opt-in or clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.