T08 · Insecure Dependencies
- Location
SKILL.md:31- Finding
Unpinned and Unnecessary Runtime Dependencies Create Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent for Alibaba Cloud ALB management, but it can make production-affecting cloud changes without uniform confirmation and saves detailed infrastructure data to disk.
Install only if you need an agent to operate Alibaba Cloud ALB resources. Use a restricted IAM role or short-lived STS credentials, run read-only inventory first, require explicit approval before any create/update/stop/remove/delete command, avoid --yes in automation, and protect or clean up saved output files because they may contain infrastructure and traffic details.
SKILL.md:31Unpinned and Unnecessary Runtime Dependencies Create Supply-Chain Risk
scripts/get_instance_status.py:229Detailed ALB Infrastructure Data Is Persisted Without Restrictive File Controls
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
next_token = resp.body.next_token
if not next_token:
break
return rules
# ---------------------------------------------------------------------------
The skill instructs use of local Python scripts, environment-based credentials, and file writes, but it does not declare any explicit tool scope or permissions boundaries. This increases the risk of over-broad execution in an agent environment because the skill can access sensitive environment variables and persist data without a clear least-privilege contract.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mkdir -p output/aliyun-alb-manage
for f in skills/network/slb/aliyun-alb-manage/scripts/*.py; do
python3 -m py_compile "$f"
done
The skill documents multiple ways to load Alibaba Cloud credentials but does not warn that these secrets must be handled carefully, not echoed, and not written into output artifacts. In this skill's context, commands also save outputs and API responses to disk, which makes accidental credential leakage or overexposure more likely during troubleshooting.
The skill lists destructive operations such as deleting load balancers, listeners, rules, and server groups without an explicit service-impact warning or confirmation requirement. In an ALB management skill, these actions can immediately disrupt production traffic or remove critical routing components, making the context especially sensitive.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
- `GetListenerAttribute` — Query listener details (including certificates/ACL)
- `ListListeners` — List listeners
- `StartListener` — Start a listener
- `StopListener` — Stop a listener
- `UpdateListenerAttribute` — Modify listener configuration
- `UpdateListenerLogConfig` — Modify listener log configuration
- `GetListenerHealthStatus` — Query listener health check status
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
- `GetListenerAttribute` — Query listener details (including certificates/ACL)
- `ListListeners` — List listeners
- `StartListener` — Start a listener
- `StopListener` — Stop a listener
- `UpdateListenerAttribute` — Modify listener configuration
- `UpdateListenerLogConfig` — Modify listener log configuration
- `GetListenerHealthStatus` — Query listener health check status
This is a markdown file, so SQP-2 applies to omissions in user-facing safety disclosures. The document explicitly enumerates sensitive fields and includes queries that surface client IPs and request URIs, but it does not warn users about privacy or data-handling implications when querying or sharing these results.
The catalog prominently lists create, update, stop, and delete scripts for production ALB resources without pairing them with explicit safety guardrails, approval requirements, or rollback cautions at the point of use. In an infrastructure-management skill, this increases the chance that an agent or operator invokes destructive actions too casually, which can lead to outages, exposure changes, or irreversible configuration loss.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# ALB Official Sources
- ALB API overview (2020-06-16):
- https://api.aliyun.com/document/Alb/2020-06-16/overview
- ALB product page in API Explorer:
- https://api.aliyun.com/product/Alb
- ALB OpenAPI metadata (machine-readable):
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# ALB Official Sources
- ALB API overview (2020-06-16):
- https://api.aliyun.com/document/Alb/2020-06-16/overview
- ALB product page in API Explorer:
- https://api.aliyun.com/product/Alb
- ALB OpenAPI metadata (machine-readable):
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# ALB Official Sources
- ALB API overview (2020-06-16):
- https://api.aliyun.com/document/Alb/2020-06-16/overview
- ALB product page in API Explorer:
- https://api.aliyun.com/product/Alb
- ALB OpenAPI metadata (machine-readable):
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# ALB Official Sources
- ALB API overview (2020-06-16):
- https://api.aliyun.com/document/Alb/2020-06-16/overview
- ALB product page in API Explorer:
- https://api.aliyun.com/product/Alb
- ALB OpenAPI metadata (machine-readable):
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
parser = argparse.ArgumentParser(description="Delete an ALB forwarding rule")
parser.add_argument("--region", required=True, help="Region ID")
parser.add_argument("--rule-id", required=True, help="Rule ID (rule-xxx)")
parser.add_argument("--yes", action="store_true", help="Skip confirmation prompt")
parser.add_argument("--json", action="store_true", help="Output as JSON")
parser.add_argument("--output", help="Write output to file")
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
parser = argparse.ArgumentParser(description="Delete an ALB forwarding rule")
parser.add_argument("--region", required=True, help="Region ID")
parser.add_argument("--rule-id", required=True, help="Rule ID (rule-xxx)")
parser.add_argument("--yes", action="store_true", help="Skip confirmation prompt")
parser.add_argument("--json", action="store_true", help="Output as JSON")
parser.add_argument("--output", help="Write output to file")
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
parser = argparse.ArgumentParser(description="Delete an ALB forwarding rule")
parser.add_argument("--region", required=True, help="Region ID")
parser.add_argument("--rule-id", required=True, help="Rule ID (rule-xxx)")
parser.add_argument("--yes", action="store_true", help="Skip confirmation prompt")
parser.add_argument("--json", action="store_true", help="Output as JSON")
parser.add_argument("--output", help="Write output to file")
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
parser = argparse.ArgumentParser(description="Delete an ALB forwarding rule")
parser.add_argument("--region", required=True, help="Region ID")
parser.add_argument("--rule-id", required=True, help="Rule ID (rule-xxx)")
parser.add_argument("--yes", action="store_true", help="Skip confirmation prompt")
parser.add_argument("--json", action="store_true", help="Output as JSON")
parser.add_argument("--output", help="Write output to file")
The script performs an irreversible operational action—removing backend servers from an ALB server group—immediately once invoked, with no interactive confirmation, no --force gate, and no safety interlock beyond an optional dry-run mode. In an agent skill context, where commands may be constructed or executed from user prompts, this increases the chance of accidental service disruption from malformed input, misunderstood intent, or automation mistakes.
This code performs a file write when --output is provided, but the only disclosure is the argument name and a post-write success message. There is no confirmation prompt or explicit warning that the command will overwrite/create a file containing potentially sensitive infrastructure health details.
No suspicious patterns detected.