Back to skill

Security audit

Alibaba Cloud Platform OpenAPI Product API Discovery

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Alibaba Cloud discovery workflow, but it uses cloud credentials with unvalidated endpoint variables and has a constrained output-path escape risk, so it deserves careful review before installation.

Use this only with short-lived, least-privilege read-only Alibaba Cloud credentials. Set endpoints only to documented Alibaba Cloud domains, avoid running it with untrusted environment variables or untrusted products JSON, and run it in an isolated workspace until endpoint and path validation are added.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/products_from_ticket_system.py:38
Finding

Cloud credentials may be used with arbitrary attacker-controlled API endpoints

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/apis_from_openapi_meta.py:77
Finding

Untrusted product metadata can escape the intended output directory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Tainted flow: 'url' from os.getenv (line 34, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/products_from_openapi_meta.py (reported line 24)May include surrounding context.

python
def fetch_json(url: str) -> dict:
    try:
        with urllib.request.urlopen(url, timeout=60) as resp:
            payload = resp.read().decode("utf-8")
    except urllib.error.URLError as exc:
        print(f"Failed to fetch {url}: {exc}", file=sys.stderr)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description describes a broad pipeline: gather product catalogs from multiple Alibaba Cloud sources, reconcile them, retrieve OpenAPI metadata, and summarize API coverage for new skill planning. This code chunk implements only a downstream comparison step: it assumes merged_products.json already exists, reads local SKILL.md files, matches products to skills by simple substring search, and outputs uncovered products. That supports part of 'coverage/gap reports for skill generation,' but it does not implement the major declared behaviors around source discovery, reconciliation, or OpenAPI metadata retrieval. Therefore the description does not accurately represent what this specific code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises a multi-source catalog discovery and reconciliation workflow plus downstream metadata collection and coverage analysis. The actual code chunk is much narrower: it uses Alibaba Cloud credentials to call only the BssOpenApi QueryProductList API, paginates through results, and saves products.json locally. There is no interaction with Ticket System or Support & Service, no product-to-API mapping, no OpenAPI version/API metadata retrieval, and no coverage/gap summarization. While the code is related to one subset of the declared purpose, it materially underdelivers relative to the description, so this is a description-versus-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code is much narrower than the declared description. It performs a single task: downloading products.json from api.aliyun.com, extracting product codes and versions, and saving the results. There is no logic for querying Ticket System, Support & Service, or BSS OpenAPI, no cross-source reconciliation, no API metadata collection beyond versions, and no coverage/gap analysis. While this script partially aligns with the 'complete product list' theme, it does not implement most of the declared functionality, so the description materially overstates the skill's behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs execution of Python scripts that read environment credentials, write files, and make network requests, but it declares no explicit tool scope or permission boundaries. In an agent setting, missing scope increases the chance the skill can access broader files, credentials, or network targets than intended, making review and runtime enforcement weaker.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated markdown headings and labels are hard-coded in Chinese (产品覆盖分析, 未覆盖产品, etc.), which imposes a specific language on output without any user opt-in or explanation. This matches the locale/language policy concern for natural-language content embedded in code.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/openapi-meta.md (reported line 8)May include surrounding context.

md
"""Fetch Alibaba Cloud product list from OpenAPI metadata endpoints.

Downloads:
  https://api.aliyun.com/meta/v1/products.json?language=EN_US

Optional env vars:
  - OPENAPI_META_LANGUAGE (default: EN_US)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/openapi-meta.md (reported line 19)May include surrounding context.

md
"""Fetch Alibaba Cloud product list from OpenAPI metadata endpoints.

Downloads:
  https://api.aliyun.com/meta/v1/products.json?language=EN_US

Optional env vars:
  - OPENAPI_META_LANGUAGE (default: EN_US)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/openapi-meta.md (reported line 29)May include surrounding context.

md
"""Fetch Alibaba Cloud product list from OpenAPI metadata endpoints.

Downloads:
  https://api.aliyun.com/meta/v1/products.json?language=EN_US

Optional env vars:
  - OPENAPI_META_LANGUAGE (default: EN_US)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/apis_from_openapi_meta.py (reported line 89)May include surrounding context.

python
"""Fetch Alibaba Cloud product list from OpenAPI metadata endpoints.

Downloads:
  https://api.aliyun.com/meta/v1/products.json?language=EN_US

Optional env vars:
  - OPENAPI_META_LANGUAGE (default: EN_US)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/products_from_openapi_meta.py (reported line 5)May include surrounding context.

python
"""Fetch Alibaba Cloud product list from OpenAPI metadata endpoints.

Downloads:
  https://api.aliyun.com/meta/v1/products.json?language=EN_US

Optional env vars:
  - OPENAPI_META_LANGUAGE (default: EN_US)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/products_from_openapi_meta.py (reported line 34)May include surrounding context.

python
"""Fetch Alibaba Cloud product list from OpenAPI metadata endpoints.

Downloads:
  https://api.aliyun.com/meta/v1/products.json?language=EN_US

Optional env vars:
  - OPENAPI_META_LANGUAGE (default: EN_US)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The code accesses access keys and optional security tokens from environment variables to authenticate with the remote service. Although the module docstring lists the required variables, it does not clearly warn users that credentials will be consumed for authenticated API access, and there is no runtime disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code performs a remote API call using credentials and optional query data such as product name and language, but there is no runtime notice, confirmation, or user-facing warning that data will be sent to the endpoint. The header documents required environment variables for developers, but it does not clearly disclose the outbound network action itself to the user at execution time.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description and workflow consistently present this skill as read-oriented discovery and summarization of Alibaba Cloud product and OpenAPI metadata. Line L100 says to ask the user before running mutating operations, which implies the skill may perform writes against cloud resources even though no such operations are described elsewhere in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The script writes analysis results to skill_gap.json and skill_gap.md, but the code provides no prior user-facing warning, confirmation, or inline comment/docstring disclosing that it will create or overwrite these files. For code-file review under this rule, file writes should have some visible disclosure unless clearly documented as part of the skill behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The generated report headings and labels are hard-coded in Chinese, which imposes a specific language choice on all users of the skill. There is no visible option to select output language or documentation explaining that the tool is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The generated markdown headings and table labels are hard-coded in Chinese, such as '产品Code', '产品名', and 'OpenAPI 产品分类汇总'. This imposes a specific language/locale on all users without opt-in or justification, which matches the natural-language locale policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.