Back to skill

Security audit

Alibaba Cloud Network ALB

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for Alibaba Cloud ALB management, but it can make production-affecting cloud changes without uniform confirmation and saves detailed infrastructure data to disk.

Install only if you need an agent to operate Alibaba Cloud ALB resources. Use a restricted IAM role or short-lived STS credentials, run read-only inventory first, require explicit approval before any create/update/stop/remove/delete command, avoid --yes in automation, and protect or clean up saved output files because they may contain infrastructure and traffic details.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned and Unnecessary Runtime Dependencies Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/get_instance_status.py:229
Finding

Detailed ALB Infrastructure Data Is Persisted Without Restrictive File Controls

Content
View full analysis
str: """Return full GetLoadBalancerAttribute response as formatted JSON.""" resp = client.get_load_balancer_attribute( alb_models.GetLoadBalancerAttributeRequest(load_balancer_id=lb_id) ) return json.dumps(resp.body.to_map(), indent=2, ensure_ascii=False, default=str) # --------------------------------------------------------------------------- # Main # --------------------------------------------------------------------------- def main() -> int: parser = argparse.ArgumentParser(description="Get ALB instance status") parser.add_argument("--region", required=True, help="Region ID, e.g. cn-hangzhou") parser.add_argument("--lb-id", required=True, help="LoadBalancer ID, e.g. alb-xxx") parser.add_argument( "--view", choices=["overview", "detail"], default="overview", help="View mode: overview (tree) or detail (full JSON). Default: overview", ) parser.add_argument("--output", help="Write output to file") args = parser.parse_args() client = create_client(args.region) if args.view == "detail": output = build_detail(client, args.lb_id) else: out ...[truncated 4676 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (19)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/get_instance_status.py (reported line 69)May include surrounding context.

python
next_token = resp.body.next_token
        if not next_token:
            break
    return rules


# ---------------------------------------------------------------------------

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill instructs use of local Python scripts, environment-based credentials, and file writes, but it does not declare any explicit tool scope or permissions boundaries. This increases the risk of over-broad execution in an agent environment because the skill can access sensitive environment variables and persist data without a clear least-privilege contract.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

Validation

bash
mkdir -p output/aliyun-alb-manage
for f in skills/network/slb/aliyun-alb-manage/scripts/*.py; do
  python3 -m py_compile "$f"
done

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documents multiple ways to load Alibaba Cloud credentials but does not warn that these secrets must be handled carefully, not echoed, and not written into output artifacts. In this skill's context, commands also save outputs and API responses to disk, which makes accidental credential leakage or overexposure more likely during troubleshooting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill lists destructive operations such as deleting load balancers, listeners, rules, and server groups without an explicit service-impact warning or confirmation requirement. In an ALB management skill, these actions can immediately disrupt production traffic or remove critical routing components, making the context especially sensitive.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/api_quick_map.md (reported line 34)May include surrounding context.

md
- `GetListenerAttribute` — Query listener details (including certificates/ACL)
- `ListListeners` — List listeners
- `StartListener` — Start a listener
- `StopListener` — Stop a listener
- `UpdateListenerAttribute` — Modify listener configuration
- `UpdateListenerLogConfig` — Modify listener log configuration
- `GetListenerHealthStatus` — Query listener health check status

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/stop_listener.py (reported line 50)May include surrounding context.

python
- `GetListenerAttribute` — Query listener details (including certificates/ACL)
- `ListListeners` — List listeners
- `StartListener` — Start a listener
- `StopListener` — Stop a listener
- `UpdateListenerAttribute` — Modify listener configuration
- `UpdateListenerLogConfig` — Modify listener log configuration
- `GetListenerHealthStatus` — Query listener health check status

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This is a markdown file, so SQP-2 applies to omissions in user-facing safety disclosures. The document explicitly enumerates sensitive fields and includes queries that surface client IPs and request URIs, but it does not warn users about privacy or data-handling implications when querying or sharing these results.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The catalog prominently lists create, update, stop, and delete scripts for production ALB resources without pairing them with explicit safety guardrails, approval requirements, or rollback cautions at the point of use. In an infrastructure-management skill, this increases the chance that an agent or operator invokes destructive actions too casually, which can lead to outages, exposure changes, or irreversible configuration loss.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sources.md (reported line 4)May include surrounding context.

md
# ALB Official Sources

- ALB API overview (2020-06-16):
  - https://api.aliyun.com/document/Alb/2020-06-16/overview
- ALB product page in API Explorer:
  - https://api.aliyun.com/product/Alb
- ALB OpenAPI metadata (machine-readable):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sources.md (reported line 6)May include surrounding context.

md
# ALB Official Sources

- ALB API overview (2020-06-16):
  - https://api.aliyun.com/document/Alb/2020-06-16/overview
- ALB product page in API Explorer:
  - https://api.aliyun.com/product/Alb
- ALB OpenAPI metadata (machine-readable):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sources.md (reported line 8)May include surrounding context.

md
# ALB Official Sources

- ALB API overview (2020-06-16):
  - https://api.aliyun.com/document/Alb/2020-06-16/overview
- ALB product page in API Explorer:
  - https://api.aliyun.com/product/Alb
- ALB OpenAPI metadata (machine-readable):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/sources.md (reported line 10)May include surrounding context.

md
# ALB Official Sources

- ALB API overview (2020-06-16):
  - https://api.aliyun.com/document/Alb/2020-06-16/overview
- ALB product page in API Explorer:
  - https://api.aliyun.com/product/Alb
- ALB OpenAPI metadata (machine-readable):

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/delete_listener.py (reported line 46)May include surrounding context.

python
parser = argparse.ArgumentParser(description="Delete an ALB forwarding rule")
    parser.add_argument("--region", required=True, help="Region ID")
    parser.add_argument("--rule-id", required=True, help="Rule ID (rule-xxx)")
    parser.add_argument("--yes", action="store_true", help="Skip confirmation prompt")
    parser.add_argument("--json", action="store_true", help="Output as JSON")
    parser.add_argument("--output", help="Write output to file")

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/delete_load_balancer.py (reported line 46)May include surrounding context.

python
parser = argparse.ArgumentParser(description="Delete an ALB forwarding rule")
    parser.add_argument("--region", required=True, help="Region ID")
    parser.add_argument("--rule-id", required=True, help="Rule ID (rule-xxx)")
    parser.add_argument("--yes", action="store_true", help="Skip confirmation prompt")
    parser.add_argument("--json", action="store_true", help="Output as JSON")
    parser.add_argument("--output", help="Write output to file")

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/delete_rule.py (reported line 43)May include surrounding context.

python
parser = argparse.ArgumentParser(description="Delete an ALB forwarding rule")
    parser.add_argument("--region", required=True, help="Region ID")
    parser.add_argument("--rule-id", required=True, help="Rule ID (rule-xxx)")
    parser.add_argument("--yes", action="store_true", help="Skip confirmation prompt")
    parser.add_argument("--json", action="store_true", help="Output as JSON")
    parser.add_argument("--output", help="Write output to file")

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/delete_server_group.py (reported line 46)May include surrounding context.

python
parser = argparse.ArgumentParser(description="Delete an ALB forwarding rule")
    parser.add_argument("--region", required=True, help="Region ID")
    parser.add_argument("--rule-id", required=True, help="Rule ID (rule-xxx)")
    parser.add_argument("--yes", action="store_true", help="Skip confirmation prompt")
    parser.add_argument("--json", action="store_true", help="Output as JSON")
    parser.add_argument("--output", help="Write output to file")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs an irreversible operational action—removing backend servers from an ALB server group—immediately once invoked, with no interactive confirmation, no --force gate, and no safety interlock beyond an optional dry-run mode. In an agent skill context, where commands may be constructed or executed from user prompts, this increases the chance of accidental service disruption from malformed input, misunderstood intent, or automation mistakes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This code performs a file write when --output is provided, but the only disclosure is the argument name and a post-write success message. There is no confirmation prompt or explicit warning that the command will overwrite/create a file containing potentially sensitive infrastructure health details.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.