Back to skill

Security audit

Alibaba Cloud Database Analyticdb Mysql

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Alibaba Cloud AnalyticDB management skill; it uses cloud credentials and writes local output as expected for that purpose, with no evidence of hidden or destructive behavior.

Install only if you intend to let the agent work with Alibaba Cloud AnalyticDB. Use least-privilege credentials, confirm the exact account, region, and resource IDs before any mutation, and avoid saving logs or outputs that contain secrets.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding
The skill advertises executable workflows that use environment variables, write files, and make network calls, yet it does not declare any permissions. This creates a transparency and policy-enforcement gap: a user or orchestrator may approve the skill without understanding that it can access cloud credentials, contact external endpoints, and persist artifacts locally.

Missing User Warnings

Low
Confidence
76% confidence
Finding
The skill references sensitive AccessKey environment variables and a shared credentials file, but it does not include an explicit warning not to print, persist, or expose those secrets in logs or output artifacts. In a skill that also performs network access and file writes, this omission increases the risk of accidental credential disclosure during troubleshooting or evidence collection.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.