Alicloud Network Dns Cli

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Alibaba Cloud DNS helper, but it can change live DNS records and uses cloud credentials.

Install this only if you want an agent to help manage Alibaba Cloud DNS. Use a RAM user or role limited to the needed DNS zones and actions, prefer environment variables or a secure credential flow over pasting long-lived secrets into shell commands, verify the CLI download source when possible, and manually confirm every domain, record name, type, value, and region before allowing changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill shows a credential configuration command that places the access key ID and secret directly on the shell command line. This can expose secrets through shell history, process listings, terminal logs, or captured transcripts, which is especially risky in agent-driven environments where commands may be recorded automatically.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal