Back to skill

Security audit

Alibaba Cloud Compute SWAS Open

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Alibaba Cloud server-management helper, but one included SSH repair script can persistently grant root SSH access and is implemented with unsafe remote shell construction.

Install only if you need Alibaba Cloud SWAS administration and can restrict credentials to the specific resources involved. Treat the SSH repair script as break-glass tooling: review the target instance, account, key fingerprint, and SSH policy before use, avoid root where possible, and do not run it with untrusted --user, --port, or --pubkey input.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fix_ssh_access.py:38
Finding

Privileged Remote Shell Injection Through Unsafely Interpolated SSH Parameters

Content
View full analysis
str: port_block = "" if port: port_block = f""" if ! grep -q '^Port' $SSHD_CONFIG; then echo 'Port {port}' >> $SSHD_CONFIG else sed -i 's/^Port.*/Port {port}/' $SSHD_CONFIG fi """ return f"""#!/bin/bash set -e USER_NAME="{user}" HOME_DIR=$(getent passwd "$USER_NAME" | cut -d: -f6) if [ -z "$HOME_DIR" ]; then echo "User $USER_NAME not found" exit 1 fi mkdir -p "$HOME_DIR/.ssh" chmod 700 "$HOME_DIR/.ssh" if ! grep -qF '{pub_key}' "$HOME_DIR/.ssh/authorized_keys" 2>/dev/null; then echo '{pub_key}' >> "$HOME_DIR/.ssh/authorized_keys" fi chmod 600 "$HOME_DIR/.ssh/authorized_keys" chown -R "$USER_NAME":"$USER_NAME" "$HOME_DIR/.ssh" SSHD_CONFIG=/etc/ssh/sshd_config if ! grep -q '^PermitRootLogin' $SSHD_CONFIG; then echo 'PermitRootLogin yes' >> $SSHD_CONFIG else sed -i 's/^PermitRootLogin.*/PermitRootLogin yes/' $SSHD_CONFIG fi if ! grep -q '^PubkeyAuthentication' $SSHD_CONFIG; then echo 'PubkeyAuthentication yes' >> $SSHD_CONFIG else sed -i 's/^PubkeyAuthentication.*/PubkeyAuthentication yes/' $SSHD_CONFIG fi {port_block} ``` The untrusted values are obtained and executed as follows: ```python parser.add_argument("--user", default="root") parser.add_argument("--port", help="Set SSH port in sshd_config") parser.add_argument("--pubkey", default="~/.ssh/id_ed25519.pub") args = parser.parse_args() pubkey_path = os.path.expanduser(args.pubkey) with open(pubkey_path, "r", encoding="utf-8") as f: pub_key = f.read().strip() script = build_script(pub_key, args.user, args.port) client = create_client(args.region) resp = client.run_command(swas_models.RunCommandRequest( region_id=args.region, instance_id=args.instance_id, n ...[truncated 2402 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/fix_ssh_access.py:64
Finding

SSH Repair Unconditionally Enables Direct Root Login

Content
View full analysis
> $SSHD_CONFIG else sed -i 's/^PermitRootLogin.*/PermitRootLogin yes/' $SSHD_CONFIG fi if ! grep -q '^PubkeyAuthentication' $SSHD_CONFIG; then echo 'PubkeyAuthentication yes' >> $SSHD_CONFIG else sed -i 's/^PubkeyAuthentication.*/PubkeyAuthentication yes/' $SSHD_CONFIG fi ``` The same script installs the supplied key into the selected account: ```bash mkdir -p "$HOME_DIR/.ssh" chmod 700 "$HOME_DIR/.ssh" if ! grep -qF '{pub_key}' "$HOME_DIR/.ssh/authorized_keys" 2>/dev/null; then echo '{pub_key}' >> "$HOME_DIR/.ssh/authorized_keys" fi chmod 600 "$HOME_DIR/.ssh/authorized_keys" chown -R "$USER_NAME":"$USER_NAME" "$HOME_DIR/.ssh" ``` ### Technical Analysis The utility defaults to the `root` account and always changes the global SSH daemon configuration to `PermitRootLogin yes`. This happens even when the operator explicitly selects a non-root user. Repairing key-based SSH access does not generally require enabling direct root login. A safer implementation can install a key for a non-root administrative account while preserving an existing root-login policy. The current behavior therefore exceeds the minimum privileges needed for routine SSH access recovery and weakens host-level access controls. The script also edits `/etc/ssh/sshd_config` in place and restarts SSH without first validating the resulting configuration with `sshd -t`. A malformed configuration may lock operators out of the server. ### Attack Path 1. An operator invokes the documented SSH repair script without specifying `--user`, causing it to select `root`. 2. The supplied public key is added to ...[truncated 924 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:27
Finding

Unpinned Python Dependencies Reduce Supply-Chain Integrity

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

This script modifies a user's authorized_keys on a remote instance via cloud command execution, granting SSH access to whoever controls the supplied public key. In the context of a cloud-management skill, this is highly sensitive because it can establish or restore persistent administrative access, especially with the default target user set to root.

Content

Scanner excerpt · scripts/fix_ssh_access.py (reported line 59)May include surrounding context.

python
mkdir -p "$HOME_DIR/.ssh"
chmod 700 "$HOME_DIR/.ssh"
if ! grep -qF '{pub_key}' "$HOME_DIR/.ssh/authorized_keys" 2>/dev/null; then
  echo '{pub_key}' >> "$HOME_DIR/.ssh/authorized_keys"
fi
chmod 600 "$HOME_DIR/.ssh/authorized_keys"

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

Appending an arbitrary public key into authorized_keys creates persistent remote access on the instance for the holder of the matching private key. Combined with RunCommand and the default root user, this is effectively a remote backdoor capability if abused, making the skill context substantially more dangerous than a local maintenance script.

Content

Scanner excerpt · scripts/fix_ssh_access.py (reported line 60)May include surrounding context.

python
mkdir -p "$HOME_DIR/.ssh"
chmod 700 "$HOME_DIR/.ssh"
if ! grep -qF '{pub_key}' "$HOME_DIR/.ssh/authorized_keys" 2>/dev/null; then
  echo '{pub_key}' >> "$HOME_DIR/.ssh/authorized_keys"
fi
chmod 600 "$HOME_DIR/.ssh/authorized_keys"
chown -R "$USER_NAME":"$USER_NAME" "$HOME_DIR/.ssh"

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
97% confidence
Finding

The YARA hit is substantively valid here because the code performs SSH key injection into authorized_keys and enables root SSH login, both classic persistence mechanisms. Even if the stated purpose is recovery or access repair, the implemented behavior can be abused to establish covert or unauthorized administrator access on cloud instances.

Content

Scanner excerpt · scripts/fix_ssh_access.py (reported line 60)May include surrounding context.

python
t {port}' >> $SSHD_CONFIG
else
  sed -i 's/^Port.*/Port {port}/' $SSHD_CONFIG
fi
"""

    return f"""#!/bin/bash
set -e
USER_NAME="{user}"
HOME_DIR=$(getent passwd "$USER_NAME" | cut -d: -f6)
if [ -z "$HOME_DIR" ]; then
  echo "User $USER_NAME not found"
  exit 1
fi

mkdir -p "$HOME_DIR/.ssh"
chmod 700 "$HOME_DIR/.ssh"
if ! grep -qF '{pub_key}' "$HOME_DIR/.ssh/authorized_keys" 2>/dev/null; then
  echo '{pub_key}' >> "$HOME_DIR/.ssh/authorized_keys"
fi
chmod 600 "$HOME_DIR/.ssh/authorized_keys"
chown -R "$USER_NAME":"$USER_NAME" "$HOME_DIR/.ssh"

SSHD_CONFIG=/etc/ssh/sshd_config
if ! grep -q '^PermitRootLogin' $SSHD_CONFIG; then
  echo 'PermitRootLogin yes' >> $SSHD_CONFIG
else
  sed -i 's/^PermitRootLogin.*/PermitRootLogin yes/' $SSHD_CONFIG
fi
if ! grep -q '^PubkeyAuthentication' $SSHD_CONFIG; then
  echo 'PubkeyAuthentication yes' >> $SSHD_CONFIG
else
  sed -i 's/^PubkeyAuthentication.*/PubkeyAuthentication yes/' $SSHD_CONFIG
fi
{port_block}

if systemctl list-unit-files | grep -q '^

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The authorized_keys file being prepared and ownership adjusted confirms the script is setting up durable SSH authentication state for the selected account. In this skill, that contributes to persistent privileged access on remote cloud instances and increases the blast radius if the script is invoked unintentionally or maliciously.

Content

Scanner excerpt · scripts/fix_ssh_access.py (reported line 62)May include surrounding context.

python
if ! grep -qF '{pub_key}' "$HOME_DIR/.ssh/authorized_keys" 2>/dev/null; then
  echo '{pub_key}' >> "$HOME_DIR/.ssh/authorized_keys"
fi
chmod 600 "$HOME_DIR/.ssh/authorized_keys"
chown -R "$USER_NAME":"$USER_NAME" "$HOME_DIR/.ssh"

SSHD_CONFIG=/etc/ssh/sshd_config

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/fix_ssh_access.py (reported line 101)May include surrounding context.

python
parser.add_argument("--instance-id", required=True)
    parser.add_argument("--user", default="root")
    parser.add_argument("--port", help="Set SSH port in sshd_config")
    parser.add_argument("--pubkey", default="~/.ssh/id_ed25519.pub")
    args = parser.parse_args()

    pubkey_path = os.path.expanduser(args.pubkey)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly expects access to environment variables, filesystem reads/writes, and shell execution, but it does not declare any explicit tool scope or permission boundaries. In a skill that can query and mutate cloud resources, this omission increases the chance an agent will use broader-than-necessary capabilities, exposing credentials from the environment and enabling unintended local or remote side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises broad mutating actions such as start/stop/reboot, disk reset, image and snapshot changes, firewall modifications, database operations, and command execution, but it does not present a prominent user-facing warning about service disruption, data loss, or security exposure. In cloud administration context, users may invoke destructive actions without understanding their operational impact, especially when the skill is framed as end-to-end management.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Cloud Assistant section explains how to run commands on target instances and retrieve outputs, but it does not explicitly warn that these commands execute on remote systems with the instance's context and can alter configuration, expose sensitive data, or disrupt workloads. Because this skill is for production cloud resources, omission of that warning makes accidental harmful execution materially more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script reads access key, secret, and security token values from environment variables to authenticate against the SWAS API, but it provides no user-facing notice that credentials will be consumed from the environment. While the module docstring explains the script uses SWAS RunCommand, it does not disclose credential access behavior.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/fix_ssh_access.py (reported line 58)May include surrounding context.

python
fi

mkdir -p "$HOME_DIR/.ssh"
chmod 700 "$HOME_DIR/.ssh"
if ! grep -qF '{pub_key}' "$HOME_DIR/.ssh/authorized_keys" 2>/dev/null; then
  echo '{pub_key}' >> "$HOME_DIR/.ssh/authorized_keys"
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/fix_ssh_access.py (reported line 62)May include surrounding context.

python
if ! grep -qF '{pub_key}' "$HOME_DIR/.ssh/authorized_keys" 2>/dev/null; then
  echo '{pub_key}' >> "$HOME_DIR/.ssh/authorized_keys"
fi
chmod 600 "$HOME_DIR/.ssh/authorized_keys"
chown -R "$USER_NAME":"$USER_NAME" "$HOME_DIR/.ssh"

SSHD_CONFIG=/etc/ssh/sshd_config

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code invokes a remote RunShellScript command against the specified instance, which is a subprocess/shell execution on a target system. While the module docstring mentions reading sshd_config, there is no confirmation prompt or user-facing warning near the operation itself to disclose that a remote command will be executed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The entire skill file is written in Chinese and does not indicate that the user can choose another language or that the locale restriction is required for a region-specific purpose. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all user-facing content in Chinese only, with no indication that users may choose another language or that the file is intentionally limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.