Aliyun Bdrc Backup
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's files and instructions match its stated purpose (discovering and using Alibaba Cloud BDRC OpenAPI metadata and guiding SDK calls); nothing in the bundle requests unrelated credentials, installs, or hidden endpoints — but pay attention before giving it live Alibaba Cloud credentials or allowing autonomous runs that could perform mutating operations.
This skill is a helper for discovering Alibaba Cloud BDRC OpenAPI metadata and guiding SDK/API calls; the included script only fetches public API metadata from api.aliyun.com and writes it to output/. Before using it: (1) Do not supply production-wide or highly privileged Alibaba Cloud keys — create least-privilege keys or use a test account. (2) Confirm the agent will ask for explicit approval before performing any mutating API calls (create/update/delete). (3) If you only want metadata, you can run the provided script locally without giving the agent credentials. (4) Verify the contents of output/ before sharing them: evidence files may include resource identifiers and timestamps (not secrets). (5) If you want the registry metadata to reflect runtime requirements, consider updating required env vars to list the Alibaba Cloud credentials so their presence is explicit.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
