Caveat verdict
vefaas
Official Volcengine FaaS CLI for deploying serverless apps; uses standard AK/SK credential flow and official distribution channel.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
Possible hardcoded credential
cookbooks/deploy-existing-code.md · code · API_KEY="your-api-key
Pipe to python — executes piped content as Python code
references/configuration.md · prose · downgraded · | Python
Popular HTTP library — network access
SKILL.md · prose · downgraded · got
Permissions & capabilities
Requires 2 environment variables. (1 sensitive: VOLC_SECRET_ACCESS_KEY). Requires 3 system binaries. (1 elevated: npm).
Is this flag fair?
Thanks — recorded.