Back to skill

Security audit

Alibaba Cloud AI Recommend AIRec

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Alibaba Cloud AIRec management helper, but users should treat it as cloud-account access because it can guide credentialed API actions.

Install this only if you want an agent to help manage Alibaba Cloud AIRec. Use least-privilege Alibaba credentials, verify region and resource IDs, require explicit approval before create/update/modify/set actions, and review any files written under output/aliyun-airec-manage/ before sharing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill uses sensitive capabilities (environment credential access, filesystem writes, and network calls) but does not declare permissions or boundaries. This reduces transparency and can lead to unexpected credential use or external communication, especially in an agent setting where operators rely on declared permissions to assess risk.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The invocation description is broad enough to match generic cloud-management or troubleshooting requests, which can cause the skill to activate in contexts where the user did not intend credentialed cloud actions. In a skill capable of mutating remote resources, over-broad triggering increases the chance of unintended API calls or unnecessary credential exposure.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs use of cloud credentials and supports mutating operations, but it lacks a clear user-facing warning that credentials will be consumed and that API calls may create, modify, or impact paid cloud resources. In this context, the absence of explicit consent and safety messaging makes accidental destructive or billable actions more likely.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.